Categories: CVE/vulnerability

Hackers Using 4 Zero-day Vulnerabilities to Attack Windows and Android Devices Remotely

During a regular investigation, the security experts at Google have detected a major hacking campaign in early 2020. The experts have uncovered a series of complicated attacks by using the zero-day flaws upon Windows and Android platforms.

Google announced a six-part report recently and detailed the flaws, and they have also mentioned all the attacks that were being carried out through two exploited servers that deliver different exploit chains by watering hole attacks.

However, the threat actors have delivered the exploits with the help of watering-hole attacks, and these attacks trade-off sites frequented by the targets of interest and tie the sites with code that installs malware on visitors’ devices.

Extractions from the exploited servers

After investigating the flaws, the Google experts have extracted some of the servers that are being exploited, and here we have mentioned them below:-

  • Four bugs in Chrome are being exploited by the renderer, one of which was still a 0-day at the point of discovery.
  • Two sandbox escape exploits violating three 0-day vulnerabilities in Windows.
  • A “privilege escalation kit” compounded of publicly that is known n-day exploits for older versions of Android.

Four zero-day exploits

There are four zero-day exploits that are detected by the experts, and here we have mentioned them below:-

  • CVE-2020-6418 – Chrome Vulnerability in TurboFan, and it was fixed in February 2020.
  • CVE-2020-0938 – Font Vulnerability on Windows, and it was fixed in April 2020.
  • CVE-2020-1020 – Font Vulnerability on Windows, and it was fixed in April 2020.
  • CVE-2020-1027 – Windows CSRSS Vulnerability, and it was fixed in April 2020.

Apart from this, Google has also affirmed a report along with its introductory blog post, and the report describes all the details of Chrome’s “infinity bug” that was used in the attacks, the Chrome exploit chains, and the Android exploit chains, post-exploitation steps on Android devices, and the Windows exploit chains.

However, all the provided details should allot other security merchants to identify the attacks on their customers and track down all the victims and other related attacks that were carried out by the same threat actor.

The experts asserted that whoever was behind the attacks has designed the exploit chains to be practiced modularly for performance and flexibility, and it has been showing clear evidence that they are specialists in what they do.

Not only this, but the experts have also presented complex code with a variety of novel exploitation techniques, mature logging, sophisticated and determined post-exploitation techniques, and high volumes of anti-analysis that are targeting the checks.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity, and hacking news updates.

Balaji

BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Recent Posts

Hack The box “Ghost” Challenge Cracked – A Detailed Technical Exploit

Cybersecurity researcher "0xdf" has cracked the "Ghost" challenge on Hack The Box (HTB), a premier…

4 hours ago

Sec-Gemini v1 – Google’s New AI Model for Cybersecurity Threat Intelligence

Google has unveiled Sec-Gemini v1, an AI model designed to redefine cybersecurity operations by empowering…

4 hours ago

U.S. Secures Extradition of Rydox Cybercrime Marketplace Admins from Kosovo in Major International Operation

The United States has successfully extradited two Kosovo nationals, Ardit Kutleshi, 26, and Jetmir Kutleshi,…

10 hours ago

Ivanti Fully Patched Connect Secure RCE Vulnerability That Actively Exploited in the Wild

Ivanti has issued an urgent security advisory for CVE-2025-22457, a critical vulnerability impacting Ivanti Connect…

2 days ago

Beware! Weaponized Job Recruitment Emails Spreading BeaverTail and Tropidoor Malware

A concerning malware campaign was disclosed by the AhnLab Security Intelligence Center (ASEC), revealing how…

2 days ago

EncryptHub Ransomware Uncovered Through ChatGPT Use and OPSEC Failures

EncryptHub, a rapidly evolving cybercriminal entity, has come under intense scrutiny following revelations of operational…

2 days ago