HT TECH wants to start sending you push notifications. Click allow to subscribe

Zero-day bug attack: Google, Microsoft, Apple scramble updates to protect you from DevilsTongue spyware

Zero-day bug attack: Google, Microsoft, Apple are looking to stop this bug. Under attack are iPhones, Android smartphones, Google Chrome, Microsoft WIndows, Apple Safari browsers and more. You can do something to save yourself.

By: HT TECH
Updated on: Aug 21 2022, 18:45 IST
Zero-day bug attack: If you have any Google, Microsoft, Apple products like iPhones, Android smartphones, or use Google Chrome, Microsoft WIndows, Safari browsers, then read on to know what you should do. (AP)

Zero-day bug attack: Google and Microsoft have released a patch to two critical vulnerabilities in their operating systems that were exploited by a spyware that has reportedly been sold to governments by Israeli developer Candiru. In its report that was released earlier this week, Citizen Labs has said that Candiru’s spyware (called DevilsTongue by Microsoft) can infect and monitor iPhones, Android smartphones, Macs, PCs and even cloud accounts. Microsoft is calling Candiru Sourgum.

Microsoft in a blog post said that the spyware was being used in precision attacks targeting more than 100 victims including politicians, human rights activists, journalists, academics, embassy workers and political dissidents in countries around the world including around the world including Palestine, Israel, Iran, Lebanon, Yemen, Spain, United Kingdom, Turkey, Armenia, and Singapore.

You may be interested in

Mobiles Tablets Laptops
5% OFF
Apple iPhone 15 Plus 256GB
  • Black
  • 6 GB RAM
  • 256 GB Storage
₹94,900₹99,900
Buy now
9% OFF
Apple iPhone 15 256GB
  • Black
  • 6 GB RAM
  • 256 GB Storage
₹90,990₹99,900
Buy now
7% OFF
Google Pixel 7 5G
  • Obsidian
  • 8 GB RAM
  • 128 GB Storage
₹40,990₹43,999
Buy now
11% OFF
Google Pixel 7A
  • Charcoal
  • 8 GB RAM
  • 128 GB Storage
₹38,990₹43,999
Buy now
27% OFF
Microsoft Surface Studio A1Y 00022
  • Platinum Silver
  • 16 GB LPDDR4X RAM
  • 512 GB SSD
₹179,990₹245,900
Buy now
7% OFF
Microsoft Surface Pro 8 8PV 00029
  • Graphite Black
  • 16 GB DDR4 RAM
  • 256 GB SSD
₹139,999₹149,999
Buy now
47% OFF
Microsoft Surface 4 5UI 00049
  • Platinum Silver
  • 8 GB DDR4 RAM
  • 256 GB SSD
₹98,000₹186,500
Buy now
28% OFF
Microsoft Surface Pro 7 M1866 VDH 00013
  • Platinum
  • 4 GB LPDDR4X RAM
  • 128 GB SSD
₹74,000₹102,990
Buy now
3% OFF
Apple iPad Pro 12 9 2022 WiFi plus Cellular 512GB
  • Silver
  • 8 GB RAM
  • 512 GB Storage
₹153,100₹157,900
Buy now
3% OFF
Apple iPad Pro 11 2022 WiFi 1TB
  • Silver
  • 16 GB RAM
  • 1 TB Storage
₹147,328₹151,900
Buy now
Apple iPad Pro 11 2022 WiFi plus Cellular 512GB
  • Silver
  • 8 GB RAM
  • 512 GB Storage
₹126,900
Buy now
3% OFF
Apple iPad Pro 12 9 2022
  • Silver
  • 8 GB RAM
  • 128 GB Storage
₹124,051₹127,900
Buy now

Also read: Looking for a smartphone? Check Mobile Finder here.

What is DevilsTongue and what does it do?

DevilsTongue is a spyware tool developed by a Tel Aviv, Israel-based company called Candiru. As Citizen Labs explains it, Candiru is a mercenary spyware firm that markets ‘untraceable’ spyware to government customers. Their product offering includes solutions for spying on computers, mobile devices, and cloud accounts.

“The €16 million project proposal allows for an unlimited number of spyware infection attempts, but the monitoring of only 10 devices simultaneously. For an additional €1.5M, the customer can purchase the ability to monitor 15 additional devices simultaneously, and to infect devices in a single additional country. For an additional €5.5M, the customer can monitor 25 additional devices simultaneously, and conduct espionage in five more countries,” Citizen Labs wrote in its report.

Once the spyware has infected a Windows PC, it exfiltrates files, exporting all messages saved in the Windows version of the popular encrypted messaging app Signal, and stealing cookies and passwords from Chrome, Internet Explorer, Firefox, Safari, and Opera browsers. Microsoft’s analysis has also shown that the spyware can also send messages from logged-in email and social media accounts directly on the victim’s computer. This could allow malicious links or other messages to be sent directly from a compromised user’s computer.

What is Microsoft doing?

To tackle this spyware, Microsoft has released a security patch for two zero-day bug vulnerabilities -- CVE-2021-31979 and CVE-2021-33771. These vulnerabilities were patched in a security update released on July 13, 2021.

“To limit these attacks, we focused on two actions. First, we built protections into our products against the unique malware Sourgum created, and we shared those protections with the security community. Second, we issued a software update that will protect Windows customers from exploits Sourgum was using to help deliver its malware,” Microsoft said in a post.

“We’ve built protections against DevilsTongue into our security products, and we’ve shared these protections with others in the security community so they can protect their customers,” the company added.

What is Google saying?

Google in a separate report by its Threat Analysis Group or TAG discovered a bunch of zero-day bug vulnerabilities in Chrome and Internet Explorer that were being used by the same company. The company found vulnerabilities CVE-2021-21166 and CVE-2021-30551 in Chrome, CVE-2021-33742 in Internet Explorer and CVE-2021-1879 in Safari WebKit. Thankfully, all the three companies -- Apple, Google and Microsoft -- have released security updates to patch these bugs.

What should I do now?

If you haven’t updated your devices -- laptops, PCs, tablets and smartphones -- now would be a good time to do so. Download the latest version of the security updates available on your devices and you are good to go.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 18 Jul, 01:00 IST

Sale

Mobiles Tablets Laptops
16% OFF
Apple iPhone 14 Plus
  • Blue
  • 6 GB RAM
  • 128 GB Storage
₹66,999₹79,900
Buy now
9% OFF
Apple iPhone 13 512GB
  • Blue
  • 4 GB RAM
  • 512 GB Storage
₹81,900₹89,900
Buy now
12% OFF
Apple iPhone 15
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹70,500₹79,900
Buy now
5% OFF
Apple iPhone 15 Pro
  • Black Titanium
  • 8 GB RAM
  • 128 GB Storage
₹127,990₹134,900
Buy now
8% OFF
Apple iPad Air 2020
  • Space Gray
  • 4 GB RAM
  • 64 GB Storage
₹45,999₹49,900
Buy now
4% OFF
Apple iPad Pro 11 WiFi Cellular 512GB
  • Silver
  • 4 GB RAM
  • 512 GB Storage
₹106,999₹111,900
Buy now
9% OFF
Apple iPad Pro 12 9 2021 WiFi plus Cellular 512GB
  • Silver
  • 8 GB RAM
  • 512 GB Storage
₹129,999₹142,900
Buy now
4% OFF
Apple iPad Pro 11 WiFi 512GB
  • Silver
  • 4 GB RAM
  • 512 GB Storage
₹106,999₹111,900
Buy now
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
40% OFF
Samsung Galaxy Book Go Laptop
  • Silver
  • 4 GB RAM
  • 128 GB SSD
₹28,690₹47,990
Buy now
22% OFF
Asus ROG Strix G15 G513RC HN085WS Laptop
  • Electro Punk
  • 16 GB RAM
  • 1 TB SSD
₹70,990₹90,990
Buy now
30% OFF
Asus ROG Strix G15 G513QY HQ032WS Laptop
  • Original Black
  • 16 GB RAM
  • 1 TB SSD
₹79,990₹113,990
Buy now
NEXT ARTICLE BEGINS