• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Predator spyware uses new infection vector for zero-click attacks

erek

8=D
2FA
Joined
Dec 19, 2005
Messages
18,228
"Google’s researchers name Intellexa as one of the most prolific commercial spyware vendors in terms of zero-day exploitation, responsible for 15 out of the 70 cases of zero-day exploitation TAG discovered and documented since 2021.

Google says Intellexa develops its own exploits and also purchases exploit chains from external entities to cover the full spectrum of required targeting.

Despite sanctions and ongoing investigations against Intellexa in Greece, the spyware operator is as active as ever, according to Amnesty International.

As Predator evolves into becoming stealthier and harder to trace, users are recommended to consider enabling extra protection on their mobile devices, like Advanced Protection on Android and Lockdown Mode on iOS."
1764894191024.png

1764894204071.png

Source: https://www.bleepingcomputer.com/ne...-new-infection-vector-for-zero-click-attacks/
 
And who's behind it? That's right, a former Israeli military officer named Tal Dilian. Predator infects through ads, which is yet another reason for ad blocker. This has created a "Predatorgate" or "Greece's Watergate" as this spyware was used to wire tap Greek financial journalists. Tal Dilian and his wife are in trial in Greece over this as well as the owner of Intellexa and the guy who bought Predator, Giannis Lavranos.
 
Article claims 0-click but doesn't mention entry vector?

Also, it is unlikely that lockdown mode and Android equivalent are effective against it.
 
  • Like
Reactions: erek
like this
Here's the thing, if enough people start getting malware through adds, the class actions will be beautiful and glorious.
If they are going to force these on us against our will, AND fail to ensure the ads they force feed us aren't poisoned, it sounds like a lawyer's wet dream.

That or it will consolidate the ad market to the major players operators think they can trust and it just gives the likes of Google and Meta more of our data and they work on encrypting their ad spaces and securing their delivery methods against interference....
 
Here's the thing, if enough people start getting malware through adds, the class actions will be beautiful and glorious.
If they are going to force these on us against our will, AND fail to ensure the ads they force feed us aren't poisoned, it sounds like a lawyer's wet dream.

That or it will consolidate the ad market to the major players operators think they can trust and it just gives the likes of Google and Meta more of our data and they work on encrypting their ad spaces and securing their delivery methods against interference....
I think a bigger concern is why are mobile devices so easily targeted by malware? Doesn't matter if it's iPhone or Android as it seems both are equally up for hacking. Ok it's through ads but why isn't this much of a problem for Windows, MacOS, and Linux? It's entirely how Android and iPhone devices work in that it's a black box. Chances are as a Windows user you have anti-virus, and that will likely detect something before it gets out of hand. MacOS and Linux are just more secure and constantly get updates to patch security holes. Nearly every 3rd party app you install on Android and iPhone has ads. If this is such a massive security hole then why does Apple and Google allow apps to have ads? Windows users should pay attention because Microsoft has been pushing ads into the OS itself.

I think we need to wake up and realize that the method Android and iOS has in terms of OS control is getting out of control. "Oh but you said open source solves everything", except that nearly every Android device has a locked boot loader. This is why Pixel phones are so popular because there's little resistance in unlocking the boot loader. The boot loader unlocking method is similar to HTC, which is the company Google bought to make their Pixel phones. Unless we fix how Android and iOS is handled on our devices, they are up for hacking.
 
I think a bigger concern is why are mobile devices so easily targeted by malware? Doesn't matter if it's iPhone or Android as it seems both are equally up for hacking. Ok it's through ads but why isn't this much of a problem for Windows, MacOS, and Linux? It's entirely how Android and iPhone devices work in that it's a black box. Chances are as a Windows user you have anti-virus, and that will likely detect something before it gets out of hand. MacOS and Linux are just more secure and constantly get updates to patch security holes. Nearly every 3rd party app you install on Android and iPhone has ads. If this is such a massive security hole then why does Apple and Google allow apps to have ads? Windows users should pay attention because Microsoft has been pushing ads into the OS itself.

I think we need to wake up and realize that the method Android and iOS has in terms of OS control is getting out of control. "Oh but you said open source solves everything", except that nearly every Android device has a locked boot loader. This is why Pixel phones are so popular because there's little resistance in unlocking the boot loader. The boot loader unlocking method is similar to HTC, which is the company Google bought to make their Pixel phones. Unless we fix how Android and iOS is handled on our devices, they are up for hacking.
Mostly because there are so many aspects of the device that exist outside of our control, and the devices themselves are built to syphon and deliver data.
By design, phones are built for harvesting data and delivering ads; until a major governing body forces them to change, this will continue to be the case.
 
Use NextDNS on mobile, it features platform-wide blocking. Blocking in a browser is great but does nothing to stop ads in apps. Remember, mobile with cellular isn't hidden via NAT, it's always exposed and allowing these apps without any type of filtering/blocking is just asking to be compromised.
 

“Predator Spyware Turns Failed Attacks Into Intelligence For Future Exploits​

wiredmikey 22 minutes ago
0
In December 2024 the Google Threat Intelligence Group published research on the code of the commercial spyware "Predator". But there's now been new research by Jamf (the company behind a mobile device management solution) showing Predator is more dangerous and sophisticated than we realized, according to SecurityWeek.

Long-time Slashdot reader wiredmikey writes: The new research reveals an error taxonomy that reports exactly why deployments fail, turning black boxes into diagnostic events for threat actors. Almost exclusively marketed to and used by national governments and intelligence agencies, the spyware also detects cybersecurity tools, suppresses forensics evidence, and has built-in geographic restrictions.”
 
How would you even protect yourself against trash like this?
Reduce threat exposure to critical assets. Stop putting everything and your mother on the internet.

We used to have seperate networks for critical systems, to somewhat mitigate these sort of risks. I guess we still do, just a lot of stuff doesn't use them.
 
  • Like
Reactions: erek
like this
Reduce threat exposure to critical assets. Stop putting everything and your mother on the internet.

We used to have seperate networks for critical systems, to somewhat mitigate these sort of risks. I guess we still do, just a lot of stuff doesn't use them.
I have IoT on a subnet, work on a subnet, users on a subnet...Unifi wifi supports wifi subnets. Also, I have sec onion sensors running ...not perfect, but better.
 
Any Edge networks / devices?
If I understand what you're asking, yes...a lot...I have a total of about 200 devices on my network. Pis, NAS, and a bunch of things besides...I have a jeston agx I ssh into as well. Is that what you're asking?

And yes, I have some risk with things like echo that could be hacked and listening, if that is your question. I have tools that listen for signatures, but I can't put sensors on every consumer device. Best I can do is isolate that network and hope they're not hacked.

edit: my personal risk is fairly low for reasons its not prudent to discuss, but I can see where things I might discuss in my house could expose my employer's IP or something to that effect. And if you're capturing enough of that data on enough people and pushing AI to look for interesting nuggets, that creates a very different risk to governments and corporations....good point. I don't talk much about my work even at home. I am not building a SCIF at home.
 
Last edited:
How would you even protect yourself against trash like this?
If you haven't noticed yet but these attacks mainly effect mobile devices like iPhone and Android, so the first course of action is to limit what you do on those devices. If you can do it in a web browser on MacOS/Linux/Windows then do that. It's stupid anyway that most apps that would happily run in a web browser need 300MB. The second thing is to not use an iPhone. Again, if you haven't noticed this seems to effect iPhone users more so than Android users. At least this was the case with Pegasus. The third option is security through obscurity. If you do use an Android phone then seek a custom rom like LineageOS, EvolutionX, and etc. If majority of people use Windows and MacOS then hacking tools will be made for these first, while Linux is an afterthought.

Finally, the best option is to vote against any politician who supports the country where these hacking software are made in.
 
  • Like
Reactions: Sherk
like this
So all i am seeing here is basic awareness, if you were born after 1995.

Blue tooth off, wi fi off, sync off, auto log in off, change passwords often, don't reuse passwords, don't use same passwords for different things. Keep everything updated. Do not save passwords, do not auto log in. etc etc?

Keep critical data physically backed up, don't be afraid to wipe and start over..

Am I missing something??
 
So all i am seeing here is basic awareness, if you were born after 1995.

Blue tooth off, wi fi off, sync off, auto log in off, change passwords often, don't reuse passwords, don't use same passwords for different things. Keep everything updated. Do not save passwords, do not auto log in. etc etc?

Keep critical data physically backed up, don't be afraid to wipe and start over..

Am I missing something??
Just do that on iPhone and Android. You don't see Pegasus and Predator getting into desktop machines. There's a reason why every other day there's an update on Windows and Linux where on Android and iPhone it's based on if the hardware manufacturer feels like it. You can install whatever OS you want on desktop PC's where iPhone's don't and Android phones sometimes may allow it, if you ask really nicely.

Just look at this shit. Keep in mind Google Pixel phones are considered friendly when it comes to doing this.

View: https://youtu.be/yi21RRiqFxI?si=aHiwy1Opf72apMr8
 
Unfortunately Samsung closed the door on OEM unlock a while ago. No custom roms. The Chinese mfrs are exceptionally difficult (lengthy) to unlock as well.
Miss the days of HTC where you could request unlock PIN via HTCDEV and when you wanted to sell the device you could RELOCK and it would be forensically identical to the factory state. Unlike samsung and their knox trip BS which of course now is moot with the closure of that ability.

Have to wonder when (Google) will follow suit. Or at least lock it down not allowing unsigned apps like micro-g, vanced, et-al. When the enshitification reaches that level I may have to go back to tinkering with boats and planes. ;-)
 
Unfortunately Samsung closed the door on OEM unlock a while ago. No custom roms. The Chinese mfrs are exceptionally difficult (lengthy) to unlock as well.
Miss the days of HTC where you could request unlock PIN via HTCDEV and when you wanted to sell the device you could RELOCK and it would be forensically identical to the factory state. Unlike samsung and their knox trip BS which of course now is moot with the closure of that ability.

Have to wonder when (Google) will follow suit. Or at least lock it down not allowing unsigned apps like micro-g, vanced, et-al. When the enshitification reaches that level I may have to go back to tinkering with boats and planes. ;-)
Google's Pixel phones are HTC, which is why the unlock method is similar. Before HTC was bought up by Google, you had to go to their website to unlock the bootloader, which is the same method Google Pixel phones use. Still a pain in the ass. Samsung devices do offer unlocked boot loaders if you by a device with their Exynos chips. Any Samsung device with a Qualcomm chip in it is locked down hard.


View: https://youtu.be/gDR6V5OdnYg?si=RtvS7rzspMkpvaha
 
Never had to get permission to unlock any pixel devices, just toggle OEM unlock, reboot (wipe) and flash. Pretty easy (so far).
Exynos Samsung devices purchased abroad would allow unlocking after 7 days uptime (we called it unlock jail period LOL!). Seems like that is no longer an option now. Too bad as the newest Exynos chipset is a beast. Oh well, still have OnePlus! 🙃

I'm rocking the USA 512/16 OnePlus 15 at the moment and like it. Don't know what all the fuss about the camera is so far it's been decent. Maybe it's everyone so fixated on the GD 100X zoom and beyond. They're all hilarious at this point. I mean if you're old like me and need to read a sign at the end of the hall or whatever. Sometimes the processing gets confused and makes the letters look chinese. Maybe that's a feature. Dunno. My Xiaomi 15 Ultra seems better in that regard. But nothing to write home about. OnePlus15 video is very good, the transition between lenses when zooming is as good as Apple's, maybe better (in hardware). I know my 17 Pro Max I can see the switching when taking video and the video when played back has it completely removed. Ai trickery. Just wish zooming didn't muck up the audio on Apple...

And the battery is BOSS on the 15. I mean I'm at 23% and have been off charge since Thursday AM with 7 hours SOT. No other phone I know of does this.
 
Back
Top