Windows, Chrome and Firefox zero-days exploited to spread malware


Cybersecurity researchers from Google’s Threat Analysis Group (TAG) are saying that a commercial company from Spain developed an exploitation network (opens in new tab) for Windows, Chrome, and Firefox, and likely sold it to government entities sometime in the past.
In a blog post published earlier this week, the TAG team says that a Barcelona-based company called Variston IT is likely tied to the Heliconia framework, which exploits n-day vulnerabilities in Chrome, Firefox, and Microsoft Defender (opens in new tab). It also says the company likely provided all the tools needed to deploy a payload to a target endpoint (opens in new tab).
No active exploitations
All the affected companies had fixed the vulnerabilities that were exploited through the Heliconia framework in 2021 and early 2022, and given that TAG did not find any active exploitations, the framework was most likely used on zero-days. Still, to fully protect against Heliconia, TAG suggests all users to keep their software up to date.
Google was first alerted to Heliconia via an anonymous submission to the Chrome (opens in new tab) bug reporting program. Whoever filed the submission added three bugs, each with instructions and an archive with the source code. They were named “Heliconia Noise”, “Heliconia Soft”, and “Files”. Further analysis has shown that they contained “frameworks for deploying exploits in the wild” and that the source code pointed to Variston IT.
Heliconia Noise is described as a framework for deploying an exploit for a Chrome renderer bug, followed by a sandbox escape. Heliconia Soft, on the other hand, is a web framework that deploys a PDF containing an exploit for Windows Defender, while Files is a set of Firefox (opens in new tab) exploits found on both Windows and Linux.
Given the fact that the Heliconia exploit works on Firefox versions 64 – 68, it was likely in use in late 2018, Google suggests.
Speaking to TechCrunch, Variston IT director Ralf Wegner said the company wasn’t aware of Google’s research and couldn’t validate the findings, but added that he’d be “surprised if such item was found in the wild.”
Commercial spyware (opens in new tab) is a growing industry, Google says, adding that it won’t stand idly as these entities sell vulnerability exploits to governments who later use it to target political opponents, journalists, human rights activists, and dissidents.
Perhaps the most famous example is the Israeli-based NSO Group and its Pegasus spyware, which landed the company on the United States’ blacklist.
Via: TechCrunch (opens in new tab)
Audio player loading… Cybersecurity researchers from Google’s Threat Analysis Group (TAG) are saying that a commercial company from Spain developed an exploitation network (opens in new tab) for Windows, Chrome, and Firefox, and likely sold it to government entities sometime in the past. In a blog post published earlier this…
Recent Posts
- Everything missing from the iPhone 16e, including MagSafe and Photographic Styles
- Reddit is reportedly experiencing some outages
- Google may be close to launching YouTube Premium Lite
- Someone wants to sell you a digital version of the antiquated typewriter but without a glued-on keyboard (no really)
- Carbon removal is the next big fossil fuel boom, oil company says
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010