Categories: Trending now

How North Korean hackers exploited Chromium browsers zero-day to steal cryptocurrencies

A North Korean hacking group exploited a previously unknown vulnerability in Google Chrome earlier this month to target cryptocurrency organisations, according to Microsoft security researchers.
The zero-day flaw, identified as CVE-2024-7971, allowed remote code execution in Chrome’s V8 JavaScript engine. Google released a fix on August 21, 2024, but not before it was used in attacks attributed to a threat actor known as Citrine Sleet.
Microsoft’s Threat Intelligence team discovered the exploit activity on August 19. They assessed with high confidence that a North Korean group was behind the attacks, which aimed to steal cryptocurrency and financial assets.
Google confirmed the vulnerability was patched but declined further comment, as reported by TechCrunch.
The hackers directed targets to a malicious domain, voyagorclub[.]space, likely using social engineering tactics. When victims connected, the Chrome exploit was delivered, followed by a Windows kernel exploit (CVE-2024-38106) to escape the browser sandbox. This allowed deployment of a rootkit called FudModule.
Citrine Sleet, also known as AppleJeus and Labyrinth Chollima, has a history of targeting the cryptocurrency sector through fake websites, job offers, and trojanized crypto applications. The group is believed to operate under North Korea’s Reconnaissance General Bureau.
“North Korean actors will likely continue targeting vulnerabilities of cryptocurrency technology firms, gaming companies, and exchanges to generate and launder funds to support the North Korean regime,” Microsoft researchers stated.
The exploit chain relied on multiple components, including the Chrome flaw and Windows kernel vulnerability. Microsoft released a fix for CVE-2024-38106 on August 13, before discovering the North Korean activity.
To mitigate risks, users should update Chrome to version 128.0.6613.84 or later and apply the latest Windows security patches. Microsoft also recommends enabling security features in Microsoft Defender and other endpoint protection products.
AD
News Today

Recent Posts

Kareena Kapoor’s Next Untitled Film With Meghna Gulzar Gets Prithviraj Sukumaran On Board

Kareena Kapoor is working with Raazi director Meghna Gulzar for her next film. The project,…

2 weeks ago

Purdue basketball freshman Daniel Jacobsen injured vs Northern Kentucky

2024-11-09 15:00:03 WEST LAFAYETTE -- Daniel Jacobsen's second game in Purdue basketball's starting lineup lasted…

2 weeks ago

Rashida Jones honors dad Quincy Jones with heartfelt tribute: ‘He was love’

2024-11-09 14:50:03 Rashida Jones is remembering her late father, famed music producer Quincy Jones, in…

2 weeks ago

Nosferatu Screening at Apollo Theatre Shows Student Interest in Experimental Cinema – The Oberlin Review

2024-11-09 14:40:03 A silent German expressionist film about vampires accompanied by Radiohead’s music — what…

2 weeks ago

What Are Adaptogens? Find Out How These 3 Herbs May Help You Tackle Stress Head-On

Let's face it - life can be downright stressful! With everything moving at breakneck speed,…

2 weeks ago

The new Mac Mini takes a small step towards upgradeable storage

Apple’s redesigned Mac Mini M4 has ditched the previous M2 machine’s SSD that was soldered…

2 weeks ago