Samsung phones are being targeted by some seriously shady zero-days

Trojan
(Image credit: Iaremenko Sergii / Shutterstock)

Three Samsung smartphone models have been found carrying vulnerabilities that were allegedly abused by a commercial surveillance vendor to spy on people and probably steal their sensitive data.

Researchers from Google's Project Zero security team said that the Samsung S10, A50, and A51 models were affected, and that only devices powered by Samsung's home-made Exynos chip were vulnerable, meaning the targets (as well as the attackers) were located in Europe, the Middle East, or Africa. 

Google has not named the vendor, but it did say that the vulnerabilities appear to be part of an infection chain. The research team only managed to get a component of the exploit app, meaning it’s still in the dark about the final payload.

Nation-states' spyware

“The first vulnerability in this chain, the arbitrary file read and write, was the foundation of this chain, used four different times and used at least once in each step,” Google Project Zero security researcher Maddie Stone wrote in a blog post outlining the threat. 

“The Java components in Android devices don’t tend to be the most popular targets for security researchers despite it running at such a privileged level,” she added.

Google also said that the exploitation works in a fashion similar to one we’ve seen earlier, when a nation-state attacker targeted individuals with powerful spyware. 

This could be referring to Hermit, an Android and iOS spyware that was developed by RCS Lab, an Italian surveillance firm. Back then, Hermit was allegedly targeting people in Italy and Kazakhstan.

Every now and then, a commercial firm gets borderline criminal with its surveillance, spyware-like software. One such example is NSO Group Technologies, an Israeli technology firm primarily known for Pegasus, its proprietary spyware capable of remote zero-click smartphone surveillance. Pegasus has landed NSO Group in the media spotlight more than once, most notably in November 2021, when the US Government banned any trade with the firm.

Via: TechCrunch

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
malware
Pegasus spyware is still targeting top business leaders
Spyware
Government-linked Italian spyware maker caught distributing malicious Android apps
Kaspersky Report on Stalkerware
Security flaw in popular stalkerware apps is exposing phone data of millions
Stalkerware
New spyware found to be snooping on thousands of Android and iOS users
an image of the Samsung Galaxy S24 Ultra
Samsung pulls curtains on classified operation called Project Infinity, where teams compete relentlessly to improve security on billions of Galaxy phones
China
Chinese police found using spyware to monitor Android devices
Latest in Security
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Polish space agency says it was hit by a cyberattack
Illustration of a hooked email hovering over a mobile phone
AWS misconfigurations reportedly used to launch phishing attacks
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
Latest in News
Michelle, Keats, and Doctor Amherst looking unimpressed and worried in The Electric State
Netflix drops trailer for The Electric State, and I'm getting serious District 9 vibes
YouTube TV
YouTube TV might be planning a big Netflix update that puts the best streaming services first
Google Pixel 9 Pro
Here are the 7 best Pixel 9 and Pixel Watch 3 features landing in March’s Pixel Feature Drop
Bang & Olufsen Beogram 4000C Saint Laurent Rive Droite Edition
Bang & Olufsen's latest reworked turntable is a masterpiece of retro revival, in a breathtaking wooden presentation box
Apple Watch Series 10
Apple unveils new Apple Watch bands – here's what's in the Spring 2025 collection
iPad Air M3
Apple makes one hardware change to the iPad Air that might be the best indicator of its true lightweight tablet intentions