3 ms·
Generally these companies use whatever method or exploit is available. Depending on how good their employees and other sources are (incl. the blackmarket, intel
by JohnStrangeII 8y ago
Generally these companies use whatever method or exploit is available. Depending on how good their employees and other sources are (incl. the blackmarket, intelligence agency contacts, etc.), it might occasionally take some time after a patch until they get a new 0-day exploit. FinFisher makes or made the same promises, according to their own advertisements.
Most of the time you don't even need a 0-day exploit, simple trojan horses/targeted phishing attacks work fine. Fake celltowers can also be used. The possibilities are nearly endless. Endpoint security is virtually nonexistent.