The exploits took advantage of vulnerabilities in the iPhone’s Safari browser and Google Chrome on Android that had already been fixed at the time of the suspected Russian campaign. Still, those exploits nevertheless could be effective in compromising unpatched devices.
According to the blog post, the exploit targeting iPhones and iPads was designed to steal user account cookies stored in Safari specifically across a range of online email providers that host the personal and work accounts of the Mongolian government. The attackers could use the stolen cookies to then access those government accounts. Google said the campaign aimed at targeting Android devices used two separate exploits together to steal user cookies stored in the Chrome browser.