Threat Analysis Group

State-backed attackers and commercial surveillance vendors repeatedly use the same exploits

an image of a blue square with the embedded text "Google" and "Threat Analysis Group"

Attack chain used in the November 2023-February 2024 campaigns targeting iOS

chart showing the attack chain in November 2023 to February 2024 campaign targeting iOS

The exploits used in the November 2023 watering hole attack (left image) and by Intellexa in September 2023 (right image) share the same trigger code.

chart showing exploits used in the November 2023 watering hole attack

Attack chain used during the July 2024 campaign targeting Google Chrome.

image showing the attack chain used during the July 2024 campaign targeting Google Chrome

The triggers for CVE-2024-5274 used in the July 2024 watering hole attack (left image) and by NSO in May 2024 (right image).

image showing the triggers for CVE-2024-5274 used in the July 2024 watering hole attack (left image) and by NSO in May 2024 (right image).
a timeline from 2021-2024 of government backed attacker activity and commercials surveillance vendor activity