TL;DR
- iLeakage: The New Safari Exploit Enables Password Stealing
- StripedFly Malware Infects 1 Million Devices, Echoes NSA-Linked Tools
- Russian APT28 Targets French Critical Networks
- CCleaner Users Hit by MOVEit Attack, Personal Data Stolen
- Octo Tempest Group Threatens Physical Violence as Social Engineering Tactic
iLeakage: The New Safari Exploit Enables Password Stealing
- The Exploit: Researchers have discovered a new side-channel attack named iLeakage. It targets Apple's A and M-series CPUs. The exploit uses speculative execution to steal sensitive data from Safari browsers on iOS and macOS devices. It can recover Gmail content, passwords, and more.
- Technical Requirements: The attack is not easy to pull off. It needs deep knowledge of Apple hardware and side-channel vulnerabilities. It also requires malicious JavaScript to be run on the victim's browser. The exploit takes about five minutes to profile a machine and another 30 seconds to extract data.
- Impact on Browsers: All browsers on iOS are affected, not just Safari. This is because Apple's policies force all iOS browsers to use Safari's WebKit engine. Chrome, Firefox, and Edge on iOS are essentially wrappers around Safari.
- Apple's Response: Apple is aware of the issue and plans to address it in an upcoming software update. However, the current mitigation is unstable and only available for Macs, not mobile devices.
StripedFly Malware Infects 1 Million Devices, Echoes NSA-Linked Tools
- Sophisticated Disguise: StripedFly malware has been active for over five years, infecting more than 1 million Windows and Linux systems. Initially thought to be a simple Monero miner, it's far more complex. It uses advanced techniques like Tor-based traffic hiding and custom EternalBlue exploits.
- Multi-Platform Infection: The malware is not picky about its targets. It infects both Windows and Linux systems. It uses trusted platforms like GitHub, GitLab, and Bitbucket for updates and has worm-like spreading capabilities. It can disable SMBv1 protocol and spread using SSH and EternalBlue.
- Data Harvesting and Control: StripedFly can do a lot once it's in the system. It can take screenshots, record audio, and harvest sensitive data like login credentials. It communicates with its Command and Control server over the Tor network, making it hard to trace.
- Deception and Future Concerns: The malware's crypto-mining function is a distraction. Its real aim is data theft and system control. It has links to ransomware like ThunderCrypt and is suspected to have origins in NSA-developed exploits. Its evasion techniques make it a significant future threat.