Stories
Slash Boxes
Comments

SoylentNews is people

Submission Preview

Link to Story

Mysterious ‘MMS Fingerprint’ Hack Used by Spyware Firm NSO Group Revealed

Accepted submission by upstart at 2024-02-17 06:49:07
News

████ # This file was generated bot-o-matically! Edit at your own risk. ████

Mysterious ‘MMS Fingerprint’ Hack Used by Spyware Firm NSO Group Revealed [securityweek.com]:

The existence of a previously unknown infection technique used by spyware firm NSO Group is suggested by a single line in a contract between NSO and the telecom regulator of Ghana.

The contract is within the documentation of the ongoing court case [securityweek.com] between WhatsApp and NSO. Labeled under ‘Infection Assisting Tools’ is a single entry titled ‘MMS Fingerprint’. NSO claims it can reveal the target device and the OS of the target device, ‘without user interaction, engagement or message opening’, and can be used against Android, Blackberry, and iOS.

There is (or has been) no known MMS fingerprint infection route. Cathal McDaid, VP of technology at Swedish telecoms security firm Enea investigated [enea.com] to learn more.

Since multiple device manufactures can be targeted, McDaid decided to look at the MMS flow rather than the individual devices. The MMS flow, writes McDaid, is somewhat ‘messy’: “Confusingly, sometimes the MMS flow is not using MMS.”

MMS was introduced when not all phones were MMS compatible. So, the developers introduced a fall-back to a type of SMS known as a binary SMS (WSP Push), used to notify the recipient MMS device’s user agent that an MMS message is waiting for retrieval.

Similarly, retrieval of the message is also not specifically ‘MMS’ – it is an HTTP GET request to the URL address contained in the waiting message. “The interesting thing here,” writes McDaid, “is that within this HTTP GET, user device information is included. It was suspected that this may be the point that targeted device information could be leaked, and the MMS Fingerprint could be ‘lifted’.” 

Enea tested this. Via MMS it was able to make the target device perform a GET to an URL on a server it controlled. This HTTP GET exposed the device’s UserAgent and x-wap-profile fields. The first identifies the OS and device. The second points to a UAProf (User Agent Profile) file that describes the capabilities of a mobile handset. Enea concealed the process by changing the binary SMS element to be a silent SMS through setting a TP-PID value of 0x40. The result was that no MMS content appears on the targeted device, and the targeted person sees anything on their phone.

All of this describes a possible infection route (which is what the NSO contract claims) rather than a specific device exploitation. However, with the information obtained, further attacks are simplified. “Both of these can be very useful for malicious actors,” says McDaid. “Attackers could use this information to exploit specific vulnerabilities or tailor malicious payloads (such as the Pegasus [securityweek.com] exploit) to the recipient device type. Or it could be used to help craft phishing campaigns against the human using the device more effectively.”

To a degree, this is all theory – but Enea has demonstrated that it is a workable MMS fingerprinting method. The firm has found no indication of it being used in the wild, but notes that it doesn’t have visibility into every operator in the world. It can be blocked by the local mobile network, while subscribers could disable MMS auto-retrieval on their handset (as recommended to defend against other MMS exploits such as Stagefright [securityweek.com].

There is no indication that this MMS fingerprinting is being used, and it can be blocked – but it exists and NSO has indicated its availability.

Related: NSO Group Used at Least 3 iOS Zero-Click Exploits in 2022: Citizen Lab [securityweek.com]

Related: El Salvador Journalists Sue NSO Group in US Over Alleged Pegasus Attacks [securityweek.com]

Related: Report: L3 Emerges as Suitor for Embattled NSO Group [securityweek.com]

Related: Spanish Judge to Seek Testimony From NSO on Pegasus Spyware [securityweek.com]

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn about active threats targeting common cloud deployments and what security teams can do to mitigate them.

Register [on24.com]

Join us for an in depth exploration of the critical nature of software and vendor supply chain security issues with a focus on understanding how attacks against identity infrastructure come with major cascading effects.

Register [securitysummits.com]

Because you can’t secure what you can’t see, having real-time asset visibility across the network is vital to maximizing security, minimizing risk, and protecting the enterprise.(Danelle Au) [securityweek.com]

Implementing a smart and timely approach to patching remains one of the primary ways for organizations to protect their networks from attackers.(Derek Manky) [securityweek.com]

The cybersecurity industry has taken limited action to reduce cybersecurity process friction, reduce mundane tasks and improve overall user experience.(Marc Solomon) [securityweek.com]

By turning incident response simulation into a continuous process and employing innovative tools, you can address the stringent requirements of the new SEC incident disclosure rules.(Torsten George) [securityweek.com]

If organizations understand the benefits SASE offers over MPLS and traditional SD-WAN, they will realize that SASE is poised to replace aging MPLS in due time.(Etay Maor) [securityweek.com]

    • Flipboard

    • Reddit

    • Whatsapp

    • https://www.securityweek.com/mysterious-mms-fingerprint-hack-used-by-spyware-firm-nso-group-revealed/">

    • Whatsapp

    • href="whatsapp://send?text=Mysterious ‘MMS Fingerprint’ Hack Used by Spyware Firm NSO Group Revealed

    • Whatsapp

    • https://www.securityweek.com/mysterious-mms-fingerprint-hack-used-by-spyware-firm-nso-group-revealed/">

    • Whatsapp

    • href="https://www.securityweek.com/cdn-cgi/l/email-protection#7d420e081f17181e094030040e09180f1412080e5d9ffde530302e5d3b14131a180f0d0f1413099ffde45d351c1e165d280e18195d1f045d2e0d040a1c0f185d3b140f105d332e325d3a0f12080d5d2f180b181c1118195b1c100d463f32392440345d1b120813195d0915140e5d1c0f09141e11185d141309180f180e0914131a5d1c13195d091512081a15095d121b5d0e151c0f14131a5d14095d0a1409155d041208535d3e15181e165d14095d120809475d1509090d0e4752520a0a0a530e181e080f1409040a181816531e12105210040e09180f1412080e5010100e501b14131a180f0d0f14130950151c1e1650080e1819501f04500e0d040a1c0f18501b140f1050130e12501a0f12080d500f180b181c11181952">

    • Email

Mobile & Wireless

Infonetics Research has shared excerpts from its Mobile Device Security Client Software market size and forecasts report, which tracks enterprise and consumer security client...

Mobile & Wireless

Samsung smartphone users warned about CVE-2023-21492, an ASLR bypass vulnerability exploited in the wild, likely by a spyware vendor.

Malware & Threats

Apple’s cat-and-mouse struggles with zero-day exploits on its flagship iOS platform is showing no signs of slowing down.

Mobile & Wireless

Apple rolled out iOS 16.3 and macOS Ventura 13.2 to cover serious security vulnerabilities.

Mobile & Wireless

Critical security flaws expose Samsung’s Exynos modems to “Internet-to-baseband remote code execution” attacks with no user interaction. Project Zero says an attacker only needs...

Fraud & Identity Theft

A team of researchers has demonstrated a new attack method that affects iPhone owners who use Apple Pay and Visa payment cards. The vulnerabilities...

Mobile & Wireless

Two vulnerabilities in Samsung’s Galaxy Store that could be exploited to install applications or execute JavaScript code by launching a web page.

Mobile & Wireless

Asus patched nine WiFi router security defects, including a highly critical 2018 vulnerability that exposes users to code execution attacks.

Close

killing-you-softly-with-backdoors dept.


Original Submission