Finnish diplomats’ phones infected with NSO Group Pegasus spyware
bleepingcomputer.com
bleepingcomputer.com
When hackers use such exploits, do they then basically have something like remote control over your phone, and can start exfiltrating data / manipulating apps while you're not paying attention? Or what do they do with it then? Are you able to tell, by seeing your phone slow down or start to have unexplained screen behaviors? Suppose that I'm logged into my Google apps on my phone, does that mean they have access to all my gmail, google docs, etc. as well?
Do these kinds of exploits also exist/get used to target people on their laptops and desktop machines as well? Or is that a little less likely, since your phone is specifically identified with you and people can easily go after your known phone number?
I wonder if there is some resource where people can read about how to detect and avoid such exploits and protect against them?
You are not able to defend yourself from targeted attacks. Period.
It is one thing to try to defend from attacks of opportunity (ie. viruses, ransomware, etc.) and another from people who actually know their job and for some reason find yourself attractive target.
Thus, the best way to respond is to not make yourself attractive target in the first place and if you need to have attractive things somewhere -- separate them from everything else.
I needed one of those things, and shopped around for a bit. And while all the big names would refuse, had waiting periods, fees, other requirements, a local credit union gave me one after signing up for a savings account immediately with a minimal or no fee.
That isn't really incentivized in this case. Assuming by medallion certificate they meant "medallion signature guarantee" [0] as established by SEC Rule 17 Ad-15 [1], a core part of the system there is that the financial institution granting it accepts liability for any forgery, up to a specified prefix amount (and the transaction will be rejected if the stamp isn't enough to cover the transaction amount). So if they "find another bank with weaker rules" who gets them to issue a stamp for a few hundred grand they are on the hook for that loss.
As a result, it's actually taken pretty seriously at least for significant amounts of money. This specific area isn't one where the guarantor gets to shrug their shoulders about it. Since they're going to be on the hook for hundreds of thousands to millions if they get it wrong, you need to be a known, established customer to even try, go in person, and someone higher level is absolutely going to looking at it personally. And even if an attacker did get past all that, the whole point is the one being attacked still hasn't lost anything.
>a local credit union gave me one after signing up for a savings account immediately with a minimal or no fee.
What prefix though? How did you check out in terms of signup (long history as resident? local connections?)? Lots of stuff goes on behind the scenes. An F alpha prefix ($100k surety, credit union) isn't the same thing as a Z ($14 million surety).
----
0: https://www.mybanktracker.com/blog/investing/medallion-signa...
Some smaller credit unions or local banks are less rigorous it seems and that incentivizes whoever wants to steal the money to go there with a fake ID, bills, etc.
> What prefix though?
F. Still a nice chunk of money for someone to steal. I guess, what I was surprised about was how different the rules were. Some quite strict, at large institutions, some pretty lax.
> How did you check out in terms of signup (long history as resident? local connections?)?
Called around and visited a few banks in the area. Not sure if / how they checked the history as a resident? There was no prior relationship with that particular credit union. As you say, perhaps behind the scene they did a rather thorough background check, but it just didn't feel that way at all based on the context.
I'm pretty sure my bank won't do that though, since I'm currently mainly using an online-only bank.
Of course, this is also the step where almost everyone, including devs, fail. How many devs know their phone to this degree? Even for our laptops, we tend to give way too much leeway to 3rd party binaries, and allow the environment to get so noisy that any kind of signal is impossible to detect. It's a depressing trade-off we (almost) all make for convenience, using the (almost) good enough assumption that we're safe in the herd. It's actually a very, very dumb assumption and I feel like it's something of a hacker golden age because of it, and as long as they don't get too greedy and spook the herd, the gravy train is here to stay.
On argument against doing even this is that a hacker can take steps to hide their process. This has happened on PCs, with rootkits that hide certain processes. This may happen for phone malware, if only to make it harder to automate detection and removal, if not to guard against watchful users (of which there are precious few).
In terms of capability, I speculate that the best an attacker can achieve is a sticky, privileged process that accepts arbitrary commands at runtime, which can be used to read the disk, analyze other running processes, install and exfil sensor data, etc. From the attacker's POV for high value targets, it probably feels like ssh'ing into a mystery box, and "see what you can do" - and they probably have a (growing) library of scripts to check for easy, juicy things. (I would guess that they would hate to see bespoke applications that have to be understood and reversed to get value out of.)
The worst-case scenario would be if the attacker somehow manages to rewrite your motherboard and/or SSD's firmware with a malicious firmware. And even if you reinstall your OS - he still manages to re-install the rootkit afterwards. I've only read about such type of malware but never have I seen or heard of anything like that in the wild.
It's not 100% foolproof I guess but at least it reduces my risk.
The security lapses will only get worse.
The most common OS are very heavily tested because of the user amount. These "secure" operating systems have niche amount of users which further reduces the amount of testing. And this is the only helping factor you - it is more beneficial to target operating systems which have a larger adaption. You need to be on high priority that they start developing exploits only for you who is using some random OS.
By comparing the number of exploits? Qubes relies on Xen, which is used by very big targets, so should be under constant attacks. Qubes uses hardware (VT-d) virtualization, which AFAIK was last time broken by the Qubes founder in 2003: https://en.wikipedia.org/wiki/Blue_Pill_(software).
This is often giving quite misleading conclusions based on what I just said - iOS for example is much more popular and heavily tested - of course the amount of exploits is much larger, because it is also much more interesting target as many are using it.
How many people are using phones/laptops which are based on Xen? Xen is commonly used on server side - not by those guys who are holding the interesting stuff on their personal devices.
AFAIK server side is often even more interesting for hackers as it's connected to big money.
> I wonder if there is some resource where people can read about how to detect and avoid such exploits and protect against them?
Protecting against the cutting edge of current nation-state attacks [1] is... well, it's not impossible but it's up there. Just don't be important/interesting enough to catch their wrath is the TL;DR.
That said, see: https://docs.mvt.re/en/latest/introduction/
[1]: https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
Stop using debit cards. Only use credit cards. Pay them via positive pay from the 3rd account.
Stop using pull. Only use push. Only target the 3rd account with positive pay as the source of funds.
You should look at family office setups anyway. It used to be something that was done at 100M level but these days the services became cheap enough that it makes sense at 10M level.
[0] Switch to a bank that supports positive pay for all electronic transactions.
My biggest paranoia wasn't about remote access though. I was really afraid someone could counterfeit my ID and just cash out as much as they could get away with. Fortunately, it hasn't happened to me.
If you have $1M+ it should not be tied to your sim card, GMail account etc... If you use the same device to access your bank accounts, and to browse internet or receive messages, you are like an idiot who does not do backups!
Using ones phone for banking, internet, and sms is completely normal. Saying that 99.9999999999999999% of the world population that owns smartphones is an idiot isn't helpful.
The idiots are the governments of the world that haven't sanctioned Israel for allowing the continued trade of these cyberweapons by their citizens.
> The idiots are the governments of the world that haven't sanctioned Israel
Sanctions against Israel are not going to make vulnerabilities and risks go away. It will just make life harder for a single provider.
For crypto currencies it may help to store them on a hardware wallet, since accessing your money will require explicit interaction. But, as far as I understand (please correct me, not up to date with the security mechanisms of hardware wallets), if your computer is compromised while doing it, you can still lose it.
The hardware wallet itself has a screen, and requires you to confirm your transactions, so generally not true
Now, if you verify that data, you are safe… if the original address was correct. But as we are talking about a sophisticated targeted attack, where did you get the original address from? Because if it was your phone or your computer, we are back to step one, as that might already be manipulated.
It’s regular government employees who get access to Pegasus. I’d be shocked if it had never been used in an unauthorized manner for straight up financial crimes.
The ideal attacker would find a way to silently steal a credential (e.g. session cookie) from your phone, then use it on a different device. That's not going to be something that makes a lot of noise on your device itself.
1. Access any data on the device regardless of application security (including applications that may request a separate password be entered as this password entry can be captured). This access includes logging into web services (e-mail included) pretending to be your phone and downloading or manipulating information stored or transmitted by the service.
2. Enable the microphone and cameras at any time.
3. Track location at any time via enabling GPS or monitoring for nearby WiFi, Bluetooth of cell tower device IDs.
4. Modify the user interface to report incorrect status, for example, incorrect battery level, GPS disabled when it's really enabled, incorrect data transfer amounts, etc.
5. Connect to other devices via WiFi or Bluetooth and interrogate them to find other devices or people nearby, and potentially attack those devices too.
An attacker can achieve similar outcomes with root access into other electronic devices--laptops, tablets, desktop computers, watches, TVs, WiFi-enabled LED light bulbs, home appliances, cars, etc. Obviously what can do with a device depends on the sensors contained within (must have a camera sensor to secretly take images or video).
Unless the attacker is reckless with turning on the video camera, microphone, GPS, WiFi, Bluetooth, etc all at once and draining battery much faster than expected, or transferring large amounts of data, you generally wouldn't notice anything different about your device. You would also probably have a hard time actively detecting the attack as the implant would be constantly watching for signs of debugging/investigation and disable/delete itself in such situations.
Generally the implant would be non-persistent only residing in volatile memory of the device that would be forgotten soon after the device is powered down. Regardless of persistence, capturing the implant from the device would be very difficult and expensive to perform for an individual, but within reach of a state actor or security researchers with a lot of time on their hands to accomplish should they have the patience.
It an implant were to be persistent and survive a device reboot, you could rapidly turn off the device (physically cut power from the battery), desolder the non-volatile memory chips and recover data similar to the process shown in [1]. There would be more steps involved if the device is encrypted (for example key is held in a TPM) but as you know the password to unlock the device, you could just ask the TPM nicely to give up the key. Failing that, there is FIB editing or other attacks against TPMs to recover keys. See [2] and [3] for some examples.
To detect a non-persistent implant, you'd follow a similar process but would have to quickly cool the volatile memory chip (see [3]) and then cut lines to the chip and insert new probes instead of desoldering it (the heat from desoldering would result in the volatile memory being cleared too quickly). Apple's Secure Enclave processor, as an example of a growing trend, encrypts and decrypts blocks of data stored in and retrieved from volatile memory so you'd additionally need to attack the Secure Enclave processor to retrieve the required keys to decrypt the volatile memory with.
The irony is that same security features which are designed to keep your device secure also inadvertently makes it prohibitively time consuming and expensive to inspect your device to detect a hidden implant in use. If you're concerned you could be a target (investigative journalists for example), the best approach is probably to assume the device is always compromised and use non-technological approaches to avoid or frustrate an attacker. Or perhaps you could find security researchers who'd love nothing more than finding and unraveling the secrets of a sophisticated implant (see [5]).
[1] https://www.youtube.com/watch?v=nXDUhhyY2rE&t=133s (recover data Samsung Galaxy directly from phone memory | HDD Recovery Services)
[2] https://www.youtube.com/watch?v=-vnik_iUuUs (Exposing The Deep-Secure Elements Of Smartcards | Christopher Tarnovsky | hardwear.io USA 2019)
[3] https://www.youtube.com/watch?v=M46Ol4gltbI (Focused Ion Beam TEM Lamella Prep Tutorial | Nicholas Rudawski)
[4] https://www.youtube.com/watch?v=Ej-Nr79bVjg (Cold Boot Attacks on Encryption Keys | J. Alex Halderman, Seth D. Schoen, Nadia Heninger, William Clarkson, William Paul, Joseph A. Calandrino, Ariel J. Feldman, Jacob Appelbaum, and Edward W. Felten | 17th USENIX Security Symposium 2008)
[5] https://citizenlab.ca/2020/12/the-great-ipwn-journalists-hac...
NSO marketing enjoy the fact they are shown as some super powered company who has been able and always will be able to get full control of every phone on earth. One dramatic news investigation showed exclusive video of NSO branded server racks[1] in an African country. Who cares about the servers? All pegasus needs is an internet connection, you could probably run it from a Chromebook
As the NSO 0-day bank has changed over the years, so have their capabilities. The NSO of 3 years ago is not the same as today and is not the same as the 2023 version. These 0-days might be known at 100 other companies with less aggressive marketing arms
[1] https://twitter.com/newsisrael13/status/1483887597025992716
There are one person companies people have never heard of capable of doing the very same like NSO.
The reality is that while NSO Group is a private company, it has deep links to the Israeli government and generally doesn't allow it's services to be used against the interests of the Israeli state.
Hiding behind a corporate name to maintain Israel's reputation in international media isn't really okay.
Not as "scary" because they aren't selling exploits to nation states and instead spying on their users/the internet.
Ike wasn't wrong.
All countries have export laws to prevent local companies from using their services and products against the country's interests.
Edit: Typed “never“ instead of “ever”
No one is running around with anger.
This is unprecedented and new information is coming out that shows how influential people, opposition and politicians were targeted worldwide.
I am not saying that these issues can/will be solved by legal and political means (especially given that it is not restricted to a single country), but it seems rather unlikely that these issues can be solved by pure technical means at the current point.
Also, Israeli government simply can't forbid their companies to do, what US companies are not forbidden to do, because that option is only available to totalitarian states.
Patching is not an issue here, but your ability to take your own(and if you are a really lucky - then others) government by balls and squeeze hard, if they do this stuff. If you do not have ability to get government by balls, then government is squeezing your balls already.
Is playing Candy Crush on your work phone really a mission-critical cyberpriority?
All the high-security executive/legislative people (at least in the US) have two phones: the personal phone and the work phone. Whoever made the decision for the work phones to be "smart" needs to be fired. The old dumb Blackberries could easily be resurrected if a government-sized buyer committed to a purchase.
For example, see FORCEDENTRY, which is one of theirs, and the technical deep dive of it is about the most amazing piece of technical writing released last year: https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
Somebody's day got ruined when that was discovered.
And kudos to the Google project zero guys for an amazing writeup.
... you don't think they're interested in closing them, do you?
The NSO isn’t a state run outfit outright but it has been used by Israel to score foreign relationship wins just like any other export and specifically arms export are used by other governments.
NSO is literarily the bargain bin option when it comes to SIGINT/COMINT, and for most of their clients they are pretty much the only option to get a high end targeted capability to compromise mobile devices.
Also for iPhones it's usually iMessage instead of SMS which supposedly is e2e encrypted.
And even without that if you get an RCE within the context of a messaging app you might be able to get most of what you need since you probably would be able to read / write arbitrary memory within the context of that process and interact with which ever APIs the app has permissions for which for messaging almost always includes microphone and camera and often location too.
The only thing you don’t get from running an exploit within the context of a single app is usually persistence but if your exploit can survive the app being suspended then as most people rarely reboot their phones you can get pretty long lived sessions too.
It's like in the dotcom days when 90% of the web was open to SQL injection.
But in multiple ways I think it's the same; like that it's obvious that security is still not a priority when building the software and that you as a user have to assume that the platforms are compromised.
There is no SQLmap for iPhones and a “Metasploit” for iPhones costs 10’s of millions and requires you to be able to negotiation contracts on a state level…
The amount of money and skill that is require to identify these vulnerabilities and develop them into functional exploits is pretty insane.
It goes well beyond what even basic RCE due to say unsafe deserialization in Java requires.
Anyone without any knowledge in programming could probably learn how to identify and exploit a SQL injection even without automated tools within days if not hours.
On the other hand even experienced developers look at something like FORCEDENTRY and can barely comprehend it.
You can go and talk about complex software and that vulnerabilities will always exists how much you want, but there is no excuse for these big companies to not fix major bugs like this within a week from when it's been reported. I don't care if that means that the developers have to postpone their fancy AI face recognition feature that will make your face look like an emoji. NO EXCUSES.
I’m not okay with anyone at all having it, so maybe if everyone could have it, the industry would have to get their shit together and actually patch the exploits.
iPhone 5S, released more than 8 years ago, is still getting updates.
for example https://citizenlab.ca/2021/09/forcedentry-nso-group-imessage...