This series of attacks used a combination of browser and operating system exploitation, sending links to targets in messengers such as WhatsApp (able to evade browser sandboxing). Leading to privilege esclation. The 'DevilsTongue' backdoor additionally exported Signal msgs.

