Home web3.0 Lazarus Group Used Fake Blockchain Game to Exploit Zero-Day Vulnerability in Google Chrome

Lazarus Group Used Fake Blockchain Game to Exploit Zero-Day Vulnerability in Google Chrome

Oct 24, 2024 am 09:54 AM
Lazarus Group Chrome vulnerability fake NFT game

The North Korean Lazarus Group of hackers used a fake blockchain-based game to exploit a zero-day vulnerability in Google’s Chrome browser and install spyware

Lazarus Group Used Fake Blockchain Game to Exploit Zero-Day Vulnerability in Google Chrome

North Korean Lazarus Group hackers have exploited a zero-day vulnerability in Google Chrome to install spyware that steals wallet credentials, using a fake blockchain-based game to carry out the attack.

The Lazarus Group’s activities were detected by Kaspersky Labs analysts in May, who reported the exploit to Google. The vulnerability has since been fixed by Google.

Playing at a high risk

The hackers’ game, which was fully playable, was promoted on LinkedIn and X. It was called DeTankZone or DeTankWar and featured tanks represented by non-fungible tokens (NFTs) that competed in a global tournament.

Interestingly, users could get infected from the game’s website even without downloading the game itself. The hackers reportedly modeled the game on the existing DeFiTankLand.

According to the report, the hackers deployed Manuscrypt malware, followed by a previously unseen “type confusion bug in the V8 JavaScript engine.” This marked the seventh zero-day vulnerability found in Chrome in 2024 up to mid-May.

“The fake game was noticed by Microsoft Security back in February. However, by the time Kaspersky was able to look into it, the threat actor had already removed the exploit from the website,” Boris Larin, principal security expert at Kaspersky, told Securelist.

Despite this, the lab went ahead and informed Google about the exploit, and Chrome fixed the vulnerability before the hackers could reintroduce it.

Screenshot from Lazarus Group’s fake game, as shared by SecureList

Related: FBI highlights 6 Bitcoin wallets linked to North Korea, urging crypto exchanges to be vigilant

North Korea has a thing for crypto

Zero-day vulnerabilities are those that a vendor is made aware of for the first time, without any patch being ready for it. In this case, it took Google 12 days to patch the vulnerability in question.

Earlier this year, another zero-day vulnerability in Chrome was exploited by a separate North Korean hacker group to target crypto holders.

As reported by Microsoft Threat Intelligence, Lazarus Group is known to have a strong preference for cryptocurrency. According to crypto crime watcher ZachXBT, the group laundered over $200 million in crypto from 25 hacks between 2020 and 2023.

The United States Treasury Department has also accused Lazarus Group of being behind the 2022 attack on Ronin Bridge, which resulted in the theft of crypto valued at over $600 million.

Over the seven-year period from 2017 to 2023, North Korean hackers stole a total of more than $3 billion in crypto, according to cybersecurity firm Recorded Future.

Magazine: Lazarus Group’s favorite exploit revealed — An analysis of crypto hacks by the notorious group

The above is the detailed content of Lazarus Group Used Fake Blockchain Game to Exploit Zero-Day Vulnerability in Google Chrome. For more information, please follow other related articles on the PHP Chinese website!

Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

Video Face Swap

Video Face Swap

Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Tools

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

Zend Studio 13.0.1

Zend Studio 13.0.1

Powerful PHP integrated development environment

Dreamweaver CS6

Dreamweaver CS6

Visual web development tools

SublimeText3 Mac version

SublimeText3 Mac version

God-level code editing software (SublimeText3)

Hot Topics

Java Tutorial
1655
14
PHP Tutorial
1252
29
C# Tutorial
1226
24
'Notorious” Conor McGregor Launches Cryptocurrency Venture, Promises to 'Change the CRYPTO Game” With His $REAL Coin 'Notorious” Conor McGregor Launches Cryptocurrency Venture, Promises to 'Change the CRYPTO Game” With His $REAL Coin Apr 06, 2025 am 10:14 AM

“Notorious nearly never happened. You want the real story? The McGregor story could've been about the lad who never left Dublin. I manifested greatness…”

BlockDAG (BDAG) Breaks Records With 2,380% Presale Price Jump, Outpacing Dogecoin (DOGE) and Kaspa (KAS) BlockDAG (BDAG) Breaks Records With 2,380% Presale Price Jump, Outpacing Dogecoin (DOGE) and Kaspa (KAS) Apr 04, 2025 am 10:16 AM

With crypto gaining traction again, three names are catching serious attention—Kaspa (KAS), Dogecoin (DOGE), and BlockDAG (BDAG)

Troller Cat ($TCAT) Is the Next Big Meme Coin Project You Need to Watch Troller Cat ($TCAT) Is the Next Big Meme Coin Project You Need to Watch Apr 04, 2025 am 11:22 AM

Ever wondered what makes meme coins soar to the moon and capture the imagination of millions? From massive returns to viral online communities

Partnership will introduce a smart launchpad, decentralized exchange, influencer marketplace, and decentralized AI infrastructure with tools for improving token launches and measuring market performan Partnership will introduce a smart launchpad, decentralized exchange, influencer marketplace, and decentralized AI infrastructure with tools for improving token launches and measuring market performan Apr 04, 2025 am 11:18 AM

This collaboration combines Generative Mind's advanced AI capabilities with Waterfall's decentralized infrastructure to develop innovative, transparent, and efficient Web3 solutions.

EOS Price Defies the Market Crash:  46% in a Week! EOS Price Defies the Market Crash: 46% in a Week! Apr 04, 2025 am 10:20 AM

While Bitcoin and the broader crypto market are under pressure, EOS is showing unexpected strength

Silver Will Surpass Both Gold and Bitcoin in Value Silver Will Surpass Both Gold and Bitcoin in Value Apr 04, 2025 am 11:16 AM

Silver has expanded its market reach within industrial sectors, leading to unprecedented increases in global demand. In Robert Kiyosaki‘s eyes, the market transition will cause silver to surpass both gold and Bitcoin in value.

Dogecoin (DOGE) Price Plummets 17% Dogecoin (DOGE) Price Plummets 17% Apr 08, 2025 am 11:20 AM

The Dogecoin price plummeted 17% in the last 24 hours to trade at $0.1365 as of 4.30 a.m. EST on trading volume that skyrocketed 271% to $2.24 billion.

Zcash (ZEC) Reaches a High of $35.69 as a Record Amount of Tokens Move Out of Circulation Zcash (ZEC) Reaches a High of $35.69 as a Record Amount of Tokens Move Out of Circulation Apr 09, 2025 am 10:36 AM

Zcash was one of the top gainers during the latest market rally, reaching a high of $35.69 as traders moved a record amount of tokens out of circulation.