Project Zero of Google identified a series of sophisticated hacking operations deep-rooted to primarily target the Windows & Android device users by exploiting a combination of their existing vulnerabilities

Continue reading
A series of sophisticated hacking operations deep-rooted to primarily target the Windows & Android device users by exploiting a combination of their existing vulnerabilities were identified by Project Zero of Google, a team of in-house security analysts specialise in discovering zero-day vulnerabilities.
It was detected in the early quarters of 2020 by collaborating with Google Threat Analysis Group (TAG). The initial results of this analysis lead to the discovery of a watering hole attack, and later, it was leveraged to deliver different exploit chains through two exploit servers to execute the cyber attack.
One of the servers targeted the Windows users, whereas the other targeted Android. Both the servers used Chrome exploits for the initial remote code execution into victims devices. And after successfully verifying the initial entry point, the deployment of OS-level exploit was done by the threat actors to gain more control over it.
Both 0-day & n-day, are included in the exploit chains of Windows, Android & Chrome. And they are referred to as bugs. However, one wasn't identified yet, whereas the other was patched but turned out to be actively exploitative.

Project Zero's analysis also reveals four render bugs in Google Chrome, two sandbox escape exploits abusing three zero-day vulnerabilities in the Windows. And a "privilege escalation kit" n-day exploits for older versions of Android containing the exploit servers at the time of discovery.
The four zero-day vulnerabilities discovered in those different exploit chains via Watering Hole Attacks were patched in the spring of 2020 by the relevant vendors:
An introductory blog post of Google published a six-part detailed report on this sophisticated operation of exploitation in the recent past, including all the details mentioned above.
However, no evidence of Android zero-day exploits hosted on the exploit servers was found. The Security Researchers of Project Zero was expecting that the threat actors might have access to Android zero-days as well, but most likely weren't hosting them on the servers during the time of discovery.
Besides, the involvement of Chrome "Infinity Bug" in this attack was also spotted according to Google's detailed report.
The exploit chain was described as "designed for efficiency & flexibility through their modularity."
"They are well-engineered, complex code with a variety of novel exploitation methods, mature logging, sophisticated and calculated post-exploitation techniques, and high volumes of anti-analysis and targeting checks," Google cited.
"We believe that teams of experts have designed and developed these exploit chains," except that no other details on the nature of the attackers or the targeted victims made available by Google.

Hugging Face did not know at the time of its own disclosure who or what was behind the intrusion