The North Korean hacking collective Lazarus Group has again popped into infamy by exploiting a zero-day vulnerability in Google’s Chrome browser, posing a significant threat to cryptocurrency users.
The group, known for executing some of the largest cryptocurrency thefts, used the exploit to install spyware on victims’ devices, enabling the theft of cryptocurrency wallet credentials.
Kaspersky Team Detects Exploit
Security researchers at Kaspersky Labs uncovered that the Lazarus Group employed a fake play-to-earn blockchain game called DeTankZone (also known as DeTankWar) as a front for their attack. This multiplayer online battle arena game, featuring non-fungible tokens (NFTs) as tanks, was promoted on social media platforms like LinkedIn and X (formerly Twitter). While appearing legitimate, the game contained a hidden malicious script that exploited a vulnerability in Chrome. Merely visiting the site triggered the infection, allowing attackers to gain full control of
We współpracy z: https://cryptodaily.co.uk/2024/10/north-korean-hackers-target-crypto-users-with-chrome-vulnerability