Chrysaor
Malware⚠️ Overview
Chrysaor is a highly sophisticated mobile spyware first publicly identified in August 2016 by Lookout and Citizen Lab, attributed to the Israeli cyber-arms company NSO Group as an early precursor to the Pegasus malware. It targeted both iOS and Android devices, primarily aiming at human rights activists, journalists, and lawyers, and belongs to the category of commercial surveillanceware with remote access trojan (RAT) capabilities.
🔧 Technical Capabilities
Chrysaor exploited three zero-day vulnerabilities in iOS—CVE-2016-4655, CVE-2016-4656, and CVE-2016-4657—to achieve a persistent jailbreak, granting kernel-level access for stealthy information theft. On Android, it leveraged the Stagefright vulnerability (CVE-2015-3864) and custom exploits to gain root privileges. The malware’s primary propagation method was spear-phishing via SMS or email containing a malicious link, with no self-spreading capability. Its command-and-control (C2) infrastructure used hardcoded IP addresses and encrypted HTTPS communications with a user-agent string mimicking AppleCoreMedia or Android WebKit to evade detection. Persistence was maintained through autostart mechanisms using plist files on iOS and broadcast receivers on Android, while evasion included runtime code decryption and removal of suspicious files after exfiltration.
📜 History & Notable Incidents
First discovered after a failed installation attempt on an iOS device belonging to a UAE human rights activist, Chrysaor was analyzed by Lookout in collaboration with Citizen Lab and published in a joint report on August 25, 2016. Notable incidents include its use against Ahmed Mansoor, a prominent Emirati activist, who received the spear-phishing SMS; no law enforcement actions directly targeting Chrysaor are publicly recorded, though NSO Group faced later sanctions from the U.S. Department of Commerce in 2021 for related Pegasus activities. The malware is referenced in MITRE ATT&CK under technique T1204.002 (User Execution: Malicious Link) and sub-technique T1543.001 (Create or Modify System Process: Launch Agent) for iOS.
🔍 Detection Indicators
Known file hashes from Lookout’s report include the iOS package com.Humanitarian.donations with MD5 7a9c9b7c2e1d3f4a5b8c0d6e7f8a9b0c (example placeholder; real hashes are listed in Lookout publication). Behavioral signatures include anomalous network traffic to suspicious IP ranges (e.g., 130.117.116.0/24) and sudden battery drain due to persistent microphone and camera activation. On iOS, evidence of a persistent jailbreak without user consent is a key indicator; on Android, the presence of the root binary or exploited mediaserver process points to compromise.
☠️ Risk & Impact
Chrysaor exfiltrates a wide range of sensitive data, including SMS messages, call logs, real-time audio recordings via the microphone, GPS location, passwords, and device photos, posing severe privacy and national security risks. The primary affected sectors are civil society organizations, legal professionals, and political activists, with the malware’s deployment facilitating targeted surveillance and potential blackmail. No direct financial losses are reported, but the reputational damage to victims and the chilling effect on free expression are profound.
🛡️ Mitigation
Mitigation focuses on keeping iOS and Android devices updated with the latest security patches, specifically those addressing the exploited zero-days (patched by Apple in iOS 9.3.5 and by Google in Android security advisories). Organizations should deploy mobile threat defense solutions such as Lookout for Enterprise and enforce strict app installation policies, while users should avoid clicking on suspicious links in unsolicited messages.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.