Google says attackers worked with ISPs to deploy Hermit spyware on Android and iOS
ictsamachar.com · Sun Jun 26 00:41:00 GMT 2022
According to research from Google's Threat Analysis Group (TAG), a sophisticated spyware campaign is using internet service providers (ISPs) to trick users into downloading malicious apps (via TechCrunch). This supports earlier research from the security company Lookout, which connected the spyware, known as Hermit, to the Italian spyware maker RCS Labs. Lookout claims that RCS Labs sells commercial spyware to various government agencies and works in the same industry as NSO Group, the notorious surveillance-for-hire business that created the Pegasus spyware.
Hermit, according to researchers at Lookout, has already been used by the governments of Italy and Kazakhstan. According to these findings, Google has identified victims in both nations and says it will inform the users who are impacted. Hermit is a modular threat that can download extra capabilities from a command and control (C2) server, according to the description in Lookout's report. By doing this, the spyware is given access to the call logs, location, pictures, and text messages on the victim's device.
Read full story at source (ictsamachar.com)