Saturday, April 5, 2025
HomeGoogleGoogle Chrome 0-Day Vulnerability Exploited in The Wild To Deploy Spyware

Google Chrome 0-Day Vulnerability Exploited in The Wild To Deploy Spyware

Published on

SIEM as a Service

Follow Us on Google News

This month came to light a zero-day vulnerability that has long been exploited by evildoers inside Google Chrome, but that has now been patched by the company. This flaw has been weaponized by an Israeli spy company and used in attacks against Middle Eastern journalists and their families.

In response to the exploitation, cybersecurity firm Avast connected the incident to Candiru (also known as Saito Tech). A Windows malware dubbed DevilsTongue has been deployed by this group on a number of occasions prior to now by exploiting previously unknown flaws.

Essentially, it is a zero-day vulnerability, with the CVE-2022-2294 designation, which has been identified in Google Chrome. As it turns out, it is memory corruption in WebRTC that was exploited in Chrome’s renderer process to be executed shellcode in a way that was not intended.

Explotaion & Targets

During the months following the July 2021 discovery of the malware by Microsoft and CitizenLab, Candiru kept a low profile for several months. 

It is likely that it took its time updating its malware in order to avoid detection by the existing detection system, that’s why it took so long.

This time it return with an updated toolset in March 2022, targeting users located in the following countries:-

  • Lebanon
  • Turkey
  • Yemen
  • Palestine

Attackers are exploiting zero-day vulnerabilities in Google Chrome to launch watering hole attacks on users. The attacks were thought to be highly targeted, but it’s not yet clear whether this is true.

It appears that the attackers in Lebanon have compromised a website that is used by news agency employees in order to carry out their duties. 

An artifact of persistent, XSS attacks was found on the compromised website, such as pages that contained the following information:-

An alert function was called with the keyword ‘test’ accompanied by a call to the Javascript function alert.

Data Collected

It is at this point that Candiru gathers more information about the victim as soon as it arrives at the exploit server. Attackers collect about 50 data points about the victim’s browser and send that information to them in the form of a profile of the victim’s computer. 

A number of information about the victim has been collected, including the:- 

  • Language
  • Timezone
  • Screen information
  • Device type
  • Browser plugins
  • Referrer
  • Device memory
  • Cookie functionality

As a result of this, it’s ensured that the exploit would be further protected and that only the targeted victims would receive it. The exploit server sends an encryption key to the victim via RSA-2048 if the data collected in the exploit has satisfied its requirements.

Using this encryption key along with the AES-256-CBC algorithm, it is possible to deliver zero-day exploits to the victim. In order to be able to deliver the exploit, an encrypted route must first be established so that it can be delivered anonymously.

Additionally, in recent years, it has been reported that since early 2021, state-sponsored hacking groups have been actively targeting journalists to spread malware and conduct espionage.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Ivanti Fully Patched Connect Secure RCE Vulnerability That Actively Exploited in the Wild

Ivanti has issued an urgent security advisory for CVE-2025-22457, a critical vulnerability impacting Ivanti...

Beware! Weaponized Job Recruitment Emails Spreading BeaverTail and Tropidoor Malware

A concerning malware campaign was disclosed by the AhnLab Security Intelligence Center (ASEC), revealing...

EncryptHub Ransomware Uncovered Through ChatGPT Use and OPSEC Failures

EncryptHub, a rapidly evolving cybercriminal entity, has come under intense scrutiny following revelations of...

PoisonSeed Targets CRM and Bulk Email Providers in New Supply Chain Phishing Attack

A sophisticated phishing campaign, dubbed "PoisonSeed," has been identified targeting customer relationship management (CRM)...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Google’s Quick Share for Windows Vulnerability Allows Remote Code Execution

Cybersecurity researchers from SafeBreach Labs have revealed new vulnerabilities in Google’s Quick Share file-transfer...

Google Cloud Platform Vulnerability Exposes Sensitive Data to Attackers

A privilege escalation vulnerability in Google Cloud Platform (GCP), dubbed "ImageRunner," was recently discovered...

Gootloader Malware Spreads via Google Ads with Weaponized Documents

The notorious Gootloader malware has resurfaced with a new campaign that combines old tactics...