This is part 5 of a 6-part series detailing a set of vulnerabilities found by Project Zero being exploited in the wild. This post covers what happens once the Android device has been successfully rooted by one of the exploits described in the previous post. Whats especially notable is that while the exploit chain only used known, and some quite old, n-day exploits, the subsequent code is extremely well-engineered and thorough. This leads us to believe that the choice to use n-days is likely not due to a lack of technical expertise.”]
Source: https://googleprojectzero.blogspot.com/2021/01/in-wild-series-android-post-exploitation.html

