Suspected North Korean hackers targeted crypto industry with Chromium zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-7971 | Type Confusion in Google Chromium V8 Enables Heap Corruption via Malicious Pages Google Chromium's V8 JavaScript engine contains a type confusion flaw (CWE-843) that lets a remote attacker trigger heap corruption through a specially crafted HTML page. The attack is triggered simply by a user loading an attacker-controlled web page, with no other interaction required. Successful exploitation of heap corruption in a browser JavaScript engine typically gives the attacker code execution within the browser process, a common first step toward broader system compromise. All users of Chromium-based browsers are affected, including Google Chrome, Microsoft Edge, Opera, and any other product embedding Chromium V8. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2024-08-26, confirming active in-the-wild exploitation, and EPSS assigns a 20.7% probability of exploitation within 30 days (97th percentile). Do: Update all Chromium-based browsers (Chrome, Edge, Opera, Brave) to the vendors' patched releases immediately and verify the installed version via chrome://version or edge://version. Per CISA's KEV required action, apply vendor mitigations or discontinue use if patches are unavailable; until patching completes, treat web browsing on high-value systems with caution and watch for vendors to publish the specific fixed version numbers. | 9.6 | 21% | KEV PoC |
| massbillions of users/installations (Chrome alone is estimated at ~3 billion+ users, plus Edge, Opera, Brave and other Chromium browsers) |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | voyagorclub.space | hey said. The hackers used a fake domain they controlled at voyagorclub[.]space — a potential reference to a now defunct crypto platform |
Full article401 words · extracted from therecord.media · click to collapse
Hackers allegedly connected to the North Korean government targeted the cryptocurrency industry using a zero-day affecting the Chromium browser. Microsoft revealed the campaign in a blog post on Friday, pointing the blame at a threat actor they call “Citrine Sleet.” The group has previously been attributed to a unit of North Korea’s Reconnaissance General Bureau. The tech giant noted that some of the tools involved in the campaign were used by other North Korean groups including one they call Diamond Sleet. The vulnerability being exploited, CVE-2024-7971, was patched by Google last week. Google acknowledged that Microsoft notified them of the vulnerability on August 19. The top cybersecurity agency in the U.S. added CVE-2024-7971 to a catalog of vulnerabilities known to have been exploited. Federal civilian agencies have until September 16 to patch the bug on government systems. According to Microsoft, Citrine Sleet focuses its attacks on financial institutions and cryptocurrency firms, creating networks of fake websites that are used to send fictitious job applications. Some incidents involved the hackers attempting to have victims download malicious crypto wallets or trading applications made to look like legitimate platforms. “Citrine Sleet most commonly infects targets with the unique trojan malware it developed, AppleJeus, which collects information necessary to seize control of the targets’ cryptocurrency assets,” they said. The hackers used a fake domain they controlled at voyagorclub[.]space — a potential reference to a now defunct crypto platform. From there, CVE-2024-7971 is exploited. A strain of malware called “FudModule” is then deployed. Microsoft noted that the malware has been in use since 2021 by other North Korean groups. At least one of the victims in this campaign was previously targeted by another North Korean group and Microsoft tied the attacks to a larger effort by Pyongyang to exploit vulnerabilities at “cryptocurrency technology firms, gaming companies, and exchanges to generate and launder funds to support the North Korean regime.” North Korea’s government has made hacking cryptocurrency platforms a key pillar of its revenue strategy, netting $3 billion from attacks between 2017 and 2023, according to United Nations investigators.
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/suspected-north-korean-hackers-crypto-chromium-zero-day