Categories: Trending now

How North Korean hackers exploited Chromium browsers zero-day to steal cryptocurrencies

A North Korean hacking group exploited a previously unknown vulnerability in Google Chrome earlier this month to target cryptocurrency organisations, according to Microsoft security researchers.
The zero-day flaw, identified as CVE-2024-7971, allowed remote code execution in Chrome’s V8 JavaScript engine. Google released a fix on August 21, 2024, but not before it was used in attacks attributed to a threat actor known as Citrine Sleet.
Microsoft’s Threat Intelligence team discovered the exploit activity on August 19. They assessed with high confidence that a North Korean group was behind the attacks, which aimed to steal cryptocurrency and financial assets.
Google confirmed the vulnerability was patched but declined further comment, as reported by TechCrunch.
The hackers directed targets to a malicious domain, voyagorclub[.]space, likely using social engineering tactics. When victims connected, the Chrome exploit was delivered, followed by a Windows kernel exploit (CVE-2024-38106) to escape the browser sandbox. This allowed deployment of a rootkit called FudModule.
Citrine Sleet, also known as AppleJeus and Labyrinth Chollima, has a history of targeting the cryptocurrency sector through fake websites, job offers, and trojanized crypto applications. The group is believed to operate under North Korea’s Reconnaissance General Bureau.
“North Korean actors will likely continue targeting vulnerabilities of cryptocurrency technology firms, gaming companies, and exchanges to generate and launder funds to support the North Korean regime,” Microsoft researchers stated.
The exploit chain relied on multiple components, including the Chrome flaw and Windows kernel vulnerability. Microsoft released a fix for CVE-2024-38106 on August 13, before discovering the North Korean activity.
To mitigate risks, users should update Chrome to version 128.0.6613.84 or later and apply the latest Windows security patches. Microsoft also recommends enabling security features in Microsoft Defender and other endpoint protection products.
AD
News Today

Recent Posts

Monaco vs. Barcelona LIVE STREAM (9/19/24): Watch Champions League online | Time, USA TV, channel

2024-09-20 02:55:03 AS Monaco faces FC Barcelona for Matchday 1 of the 2024-25 Champions League…

6 mins ago

Barcelona: La apuesta por los jóvenes da frutos, pero ¿durará?

2024-09-20 02:45:03 19 de sep, 2024, 10:27 ETFlick no lo sabe, pero hay una sorpresa…

16 mins ago

Is Apple Cider Vinegar Good For Your Digestive Health? Hear From An Expert

Apple cider vinegar, also known as ACV, has become a go-to drink for many in…

31 mins ago

The Buckingham Murders: Money lessons you can learn from Kareena Kapoor Khan’s latest thriller

Kareena Kapoor Khan alone carried the film Jaane Jaan (2023) on her capable shoulders despite…

36 mins ago

Amazon debuts Project Amelia, an AI assistant for sellers

Amazon sellers now have access to an AI assistant designed to help grow their business…

41 mins ago

Beyonce Attends Dr. Gloria Carter’s Birthday Wearing Chloe Fall 2024 Brown Ruffled Mini Dress

Beyonce and Jay Z greeted the Isley Brothers, who performed at Dr. Gloria Carter’s birthday…

46 mins ago