Cyber Security News

Lazarus APT Hackers Exploit Chrome Zero-Day via Cryptocurrency Game

The notorious Lazarus Advanced Persistent Threat (APT) group has exploited a zero-day vulnerability in the Google Chrome browser, using a cryptocurrency-themed game as a lure.

The attack highlights the evolving tactics of this North Korean-linked group, known for its financial motivations and advanced social engineering strategies.

On May 13, 2024, Kaspersky’s security systems detected a new infection on a personal computer in Russia, revealing the exploitation of a zero-day vulnerability in Google Chrome.

The attack was traced back to a website, detankzone[.]com, which masqueraded as a legitimate product page for a decentralized finance (DeFi) NFT-based multiplayer online battle arena (MOBA) tank game.

National Cybersecurity Awareness Month Cyber Challenges – Test your Skills Now

Exploitation of Vulnerabilities

However, beneath its seemingly innocuous facade lay a malicious script designed to exploit users’ browsers and gain control over their systems.

The exploit leveraged two vulnerabilities. The first allowed attackers to read and write memory within the Chrome process, while the second bypassed the V8 sandbox, a security feature designed to isolate memory and prevent unauthorized code execution.

Chrome Zero-day via Game

This sophisticated attack enabled the hackers to execute arbitrary code on victims’ machines.

Upon discovering the exploit, Kaspersky promptly reported it to Google. Within two days, Google released an update addressing the vulnerability (CVE-2024-4947) in Chrome version 125.0.6422.60.

Additionally, Google blocked access to detankzone[.]com and related malicious sites to protect users from further attacks.

Lazarus APT’s campaign extended beyond technical exploits to include elaborate social engineering efforts. The group built a social media presence to promote their fake game, even reaching out to cryptocurrency influencers to amplify their reach.

This multifaceted approach underscores Lazarus’s commitment to crafting convincing narratives around their attacks.

The attackers developed a seemingly legitimate game as part of their deception strategy. The game, initially appearing as a genuine product developed in Unity, was based on stolen source code from an existing game called DeFiTankLand (DFTL).

This added layer of authenticity made the malicious campaign more credible and enticing to potential victims.

The Lazarus group’s use of zero-day vulnerabilities and advanced social engineering tactics poses significant threats to individuals and organizations. Their ability to adapt and innovate in their attack methods suggests that such threats will persist and evolve.

Staying vigilant is crucial for end-users. Regularly updating software and exercising caution when interacting with unsolicited links or downloads can mitigate risks.

As browser developers continue enhancing security features like JIT compilers and sandboxes, users are encouraged to keep their systems updated to protect against emerging threats.

Threat actors continue refining their techniques and leveraging new technologies, such as generative AI for social engineering; cybersecurity measures must evolve accordingly to safeguard against these sophisticated attacks.

Free Webinar on How to Protect Small Businesses Against Advanced Cyberthreats -> Watch Here

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago