Sweet QuaDreams or Nightmare Before Christmas? Dissecting an iOS O-day

No ratings

Presented at Bluehat / BlueHat India 2024 by

Not quite nation states but not quite independent corporations, “private sector offensive actors” (PSOAs) have become one of the latest sophisticated threats. These companies develop and sell surveillance and intrusion capabilities to governments around the world. While some governments responsibly use the tools to track criminals and terrorists, others instead opt to abuse the tools by spying on journalists, dissidents, or members of their political opposition. The conversation about PSOAs often centers around NSO Group, and their infamous zero-click “Pegasus” spyware. However, an industry of competitors abounds. While the final payload of Pegasus has proved elusive for some time, Microsoft and Citizen Lab successfully obtained and analyzed the final payload associated with a separate zero-click mobile threat fielded by an NSO competitor, “QuaDream”. QuaDream’s spyware was used against targets around the world, including journalists, political opposition figures, and an NGO worker. This sample was deemed “KingsPawn” by Microsoft and the exploit named “ENDOFDAYS” by CitizenLab. So what does it take to develop such a zero-click, zero-day attack? What does a modern, top- tier, iOS spyware implant look like? What is the state-of-the-art in mobile threats? And what is the likelihood of you or your employees being targeted by such an attack? In this talk, Bill Marczak and Christine Fossaceca discuss the discovery of QuaDream’s spyware, outline the zero-click exploit likely used to deliver it, and share their experience reversing engineering the attack surface from the ground up.