Cyber Security News

iPhones Hacked via Zero-click Exploit to Drop QuaDream Spyware

In collaboration with Citizen Lab, Microsoft recently uncovered an alarming discovery about QuaDream, an Israel-based firm. 

The company was found to be behind the development of commercial spyware dubbed “KingsPawn” that uses a zero-click exploit called “ENDOFDAYS” to compromise high-risk individuals’ iPhones.

Threat actors exploited a zero-day vulnerability that affected the iPhones running iOS 14 or later versions up to 14.4.2. 

Between January 2021 and November 2021, the attack employed a sophisticated backdated technique involving “invisible iCloud calendar invitations,” making them nearly impossible to detect.

Zero-click Exploit to Drop Spyware

One way the ENDOFDAYS exploit could remain undetected by targets was by using backdated timestamps on iCloud calendar invitations.

When all these backdated invitations were sent to iOS users, they were automatically added to their calendars without the user having to do anything, reads Microsoft report.

This automatic addition provided a stealthy means for the exploit to run without the user’s knowledge.

QuaDream’s spyware has compromised a total of five civil society organizations in the following regions:-

  • North America
  • Central Asia
  • Southeast Asia
  • Europe
  • The Middle East

While here below, we have mentioned the victims that are primarily targeted:-

  • Journalists
  • Political opposition figures
  • An NGO worker

The surveillance malware, KingsPawn used was equipped with a stealthy feature, the ability to self-delete and erase all traces of its existence on victims’ iPhones. 

This design feature enabled the malware to evade detection, leaving victims unaware that their devices had been compromised. This self-destructing feature was detected on the victims’ devices, revealing a name for the process used by the spyware.

Capabilities of KingsPawn

Based on Citizen Lab’s analysis, the spyware discovered in this attack campaign appears highly sophisticated and invasive since it boasts many features.

Here below, we have mentioned the complete list of capabilities that KingsPawn features:-

  • Get device information
  • Recording audio from phone calls
  • Recording audio from the microphone
  • Wi-Fi information
  • Cellular information
  • Search for files
  • Retrieve files
  • Use the device camera in the background
  • Get device location
  • Monitor phone calls
  • Access the iOS keychain
  • Generate an iCloud time-based one-time password (TOTP)

Apart from this, QuaDream servers were discovered across multiple countries, including:-

  • Bulgaria
  • The Czech Republic
  • Hungary
  • Ghana
  • Israel
  • Mexico
  • Romania
  • Singapore
  • United Arab Emirates
  • Uzbekistan

This discovery shows that the spyware used to target high-risk individuals is an alarming reminder of the scope and scale of the mercenary spyware industry.

This industry encompasses a vast network of companies, making it challenging to pinpoint any one culprit responsible for such attacks.

The prevalence of commercial spyware provided by surveillance tech providers has raised concerns about the security of vulnerable Android and iOS devices. 

The spyware is often deployed on devices susceptible to zero-day flaws, exploiting previously unknown vulnerabilities and granting the attacker broad access to the device’s data and functions.

Why do Organizations need Unified endpoint management – 

Related Read:

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago