North Korean Lazarus Group Exploits Chrome Vulnerability in DeFi Game Attack on Crypto Investors

Share This Post

The North Korean hacking collective Lazarus Group has launched a targeted cyberattack on cryptocurrency investors by exploiting a fake decentralized finance (DeFi) game and leveraging a newly discovered Google Chrome zero-day vulnerability. This scheme, which included the use of malware and advanced browser exploits, allowed Lazarus to infiltrate sensitive user information and posed significant risks for crypto asset holders.

Background on the Attack

In May 2024, cybersecurity researchers at Kaspersky uncovered a novel method of attack by Lazarus when they detected the Manscrypt backdoor malware being used to exploit Google Chrome’s vulnerability CVE-2024-4947. The group created a fraudulent game site, “DeTankZone,” marketed as an NFT-based multiplayer online battle arena game. This fake game site was heavily promoted across social media, LinkedIn, and even spear-phishing emails designed to lure cryptocurrency enthusiasts and investors into the trap.

Exploiting the Zero-Day Vulnerability

Lazarus Group’s attack leveraged a type confusion flaw in Chrome’s code, tracked as CVE-2024-4947, which allowed them to corrupt memory and ultimately exfiltrate sensitive data. A hidden script on the game’s website abused this flaw, gaining access to browser histories, cookies, passwords, and authentication tokens. Researchers noted that this exploit allowed attackers to remotely execute malicious code, further enhancing their reach by collecting data on operating systems, BIOS information, and CPU details.

Also read: Indicted NYC Mayor Eric Adams’ Crypto Promises Under Scrutiny Amid Legal Troubles

Impact on Crypto Investors

This attack specifically aimed to compromise the wallets and exchanges used by investors. By accessing private user data through Chrome’s vulnerabilities, Lazarus Group managed to exfiltrate crucial information that could be leveraged to access and drain crypto assets. Security experts have raised alarms over Lazarus’s ability to combine social engineering with technical exploits, making it increasingly difficult for individuals and institutions to detect or counteract these attacks effectively.

Response from the Security Community

The CVE-2024-4947 vulnerability has since been patched by Google, following its discovery by Kaspersky’s team. Security experts are advising crypto investors to keep their software up-to-date and to remain cautious when accessing DeFi or NFT-based applications, especially those promoted through unverified social channels.

Cybersecurity researchers and professionals emphasize the importance of rigorous security practices, including multi-factor authentication and phishing awareness, as essential defenses against the evolving tactics of groups like Lazarus.

Related Posts

How to Warm Up an X (Twitter) Account for SMM

Below is a comprehensive, step-by-step guide on how to...

$KEK: The OG Solana Meme Coin That Even Elon Loves!

The internet is buzzing, and the meme economy is...

F1 Extends Crypto.com Sponsorship to 2030: A Milestone in Global Sports and Cryptocurrency

Formula One (F1) has solidified its collaboration with cryptocurrency...

Turkey Tightens Crypto Regulations with $425 AML Threshold for $170 Billion Market

As Turkey’s cryptocurrency sector continues to expand, the government...

SBI VC Trade to Absorb Hacked Crypto Exchange DMM, Customer Accounts Ready by March

In a major development for Japan’s cryptocurrency sector, SBI...
pax-gold
PAX Gold (PAXG) $ 2,702.30 0.02%
mog-coin
Mog Coin (MOG) $ 0.000002 6.43%
dogs-2
Dogs (DOGS) $ 0.000445 5.08%
sui
Sui (SUI) $ 4.70 5.04%
kaspa
Kaspa (KAS) $ 0.141968 6.08%
bitcoin
Bitcoin (BTC) $ 103,742.80 1.43%
ethereum
Ethereum (ETH) $ 3,306.21 3.52%
bnb
BNB (BNB) $ 702.23 3.07%
solana
Solana (SOL) $ 240.04 9.58%
venko
VENKO ($VENKO) $ 0.000002 9.49%
tron
TRON (TRX) $ 0.241714 2.24%
avalanche-2
Avalanche (AVAX) $ 39.46 4.37%
shiba-inu
Shiba Inu (SHIB) $ 0.000023 6.05%
pepe
Pepe (PEPE) $ 0.000019 5.51%
dogwifcoin
dogwifhat (WIF) $ 1.85 0.37%
near
NEAR Protocol (NEAR) $ 5.49 1.83%
injective-protocol
Injective (INJ) $ 24.85 2.29%
sei-network
Sei (SEI) $ 0.401843 4.79%
dogecoin
Dogecoin (DOGE) $ 0.401036 3.41%
the-open-network
Toncoin (TON) $ 5.36 4.65%
xrp
XRP (XRP) $ 3.17 4.53%
bonk
Bonk (BONK) $ 0.000034 11.64%
floki
FLOKI (FLOKI) $ 0.000174 2.81%
popcat
Popcat (POPCAT) $ 0.637868 7.01%
based-brett
Brett (BRETT) $ 0.119257 10.55%
moo-deng
Moo Deng (MOODENG) $ 0.176966 11.71%