EletiofeGoogle Moves to Block Invasive Spanish Spyware Framework

Google Moves to Block Invasive Spanish Spyware Framework

-

- Advertisment -

The commercial spyware industry has increasingly come under fire for selling powerful surveillance tools to anyone who can pay, from governments to criminals around the world. Across the European Union, details of how spyware has been used to target activists, opposition leaders, lawyers, and journalists in multiple countries have recently touched off scandals and calls for reform. Today, Google’s Threat Analysis Group announced action to block one such hacking tool that targeted desktop computers and was seemingly developed by a Spanish firm.

The exploitation framework, dubbed Heliconia, came to Google’s attention after a series of anonymous submissions to the Chrome bug reporting program. The disclosures pointed to exploitable vulnerabilities in Chrome, Windows Defender, and Firefox that could be abused to deploy spyware on target devices, including Windows and Linux computers. The submission included source code from the Heliconia hacking framework and called the vulnerabilities Heliconia Noise, Heliconia Soft, and Files. Google says the evidence points to the Barcelona-based tech firm Variston IT as the developer of the hacking framework.

“The findings indicate that we have many small players within the spyware industry, but with strong capabilities related to zero days,” TAG researchers told WIRED, referring to unknown, unpatched vulnerabilities. 

Variston IT did not respond to a request for comment from WIRED. The company’s director, Ralf Wegner, told TechCrunch that Variston was not given the opportunity to review Google’s research and could not validate it. He added that he “would be surprised if such item was found in the wild.” Google confirmed that the researchers did not contact Variston IT in advance of publication, as is the company’s standard practice in these types of investigations. 

Google, Microsoft, and Mozilla patched the Heliconia vulnerabilities in 2021 and 2022, and Google says it has not detected any current exploitation of the bugs. But evidence in the bug submissions indicates that the framework was likely being used to exploit the flaws starting in 2018 and 2019, long before they were patched. Heliconia Noise exploited a Chrome renderer vulnerability and a sandbox escape, while Heliconia Soft used a malicious PDF laced with a Windows Defender exploit, and Files deployed a group of Firefox exploits for Windows and Linux. TAG collaborated on the research with members of Google’s Project Zero bug-hunting group and the Chrome V8 security team.

The fact that Google does not see current evidence of exploitation may mean that the Heliconia framework is now dormant, but it might also indicate that the hacking tool has evolved. “It could be there are other exploits, a new framework, their exploits didn’t cross our systems, or there are other layers now to protect their exploits,” TAG researchers told WIRED.

Ultimately, the group says its goal with this type of research is to shed light on the commercial spyware industry’s methods, technical capabilities, and abuses. TAG created detections for Google’s Safe Browsing service to warn about Heliconia-related sites and files, and the researchers emphasize that it’s always important to keep software up to date.

“The growth of the spyware industry puts users at risk and makes the internet less safe,” TAG wrote in a blog post about the findings. “And while surveillance technology may be legal under national or international laws, they are often used in harmful ways to conduct digital espionage against a range of groups.”

Latest news

Somehow This $10,000 Flame-Thrower Robot Dog Is Completely Legal in 48 States

If you've been wondering when you’ll be able to order the flame-throwing robot that Ohio-based Throwflame first announced last...

‘Metaphor: ReFantazio’ Steals the Best Ideas From ‘Persona 5’

When it came time to make Metaphor: ReFantazio, developer Atlus had a guiding principle: make a video game that...

How NASA Repaired Voyager 1 From 15 Billion Miles Away

Throughout the five months of troubleshooting, Voyager's ground team continued to receive signals indicating the spacecraft was still alive....

Can the First Amendment Save TikTok?

On Wednesday, President Joe Biden signed a law that could effectively ban TikTok if the company does not divest...
- Advertisement -

‘ArcaneDoor’ Cyberspies Hacked Cisco Firewalls to Access Government Networks

Network security appliances like firewalls are meant to keep hackers out. Instead, digital intruders are increasingly targeting them as...

President Biden Signs Bill That Could Ban TikTok

President Joe Biden signed a bill on Wednesday that could ban TikTok from operating within the United States as...

Must read

Somehow This $10,000 Flame-Thrower Robot Dog Is Completely Legal in 48 States

If you've been wondering when you’ll be able to...

‘Metaphor: ReFantazio’ Steals the Best Ideas From ‘Persona 5’

When it came time to make Metaphor: ReFantazio, developer...
- Advertisement -

You might also likeRELATED
Recommended to you