Threat Analysis Group

State-backed attackers and commercial surveillance vendors repeatedly use the same exploits

an image of a blue square with the embedded text "Google" and "Threat Analysis Group"
chart showing the attack chain in November 2023 to February 2024 campaign targeting iOS

Attack chain used in the November 2023-February 2024 campaigns targeting iOS

chart showing exploits used in the November 2023 watering hole attack

The exploits used in the November 2023 watering hole attack (left image) and by Intellexa in September 2023 (right image) share the same trigger code.

image showing the attack chain used during the July 2024 campaign targeting Google Chrome

Attack chain used during the July 2024 campaign targeting Google Chrome.

image showing the triggers for CVE-2024-5274 used in the July 2024 watering hole attack (left image) and by NSO in May 2024 (right image).

The triggers for CVE-2024-5274 used in the July 2024 watering hole attack (left image) and by NSO in May 2024 (right image).

a timeline from 2021-2024 of government backed attacker activity and commercials surveillance vendor activity