ZeroHour
Infosecurity Magazinepublished ()ingested Alessandro Mascellino

Lazarus Group Exploits Google Chrome Flaw in New Campaign

criticalThreat actorimportance 60CVE-2024-4947

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-4947
V8 Type Confusion in Google Chrome Actively Exploited by Lazarus Group

CVE-2024-4947 is a type-confusion flaw (CWE-843) in the V8 JavaScript engine of Google Chrome, rated High by Chromium with a CVSS 3.1 score of 9.6. An attacker triggers it by luring a user to a crafted HTML page, causing V8 to misinterpret object types and enabling execution of arbitrary code inside the Chrome sandbox. Exploitation of the V8 bug alone keeps the attacker sandboxed, but it is a typical first stage of a browser exploit chain and can be paired with sandbox-escape techniques for broader system access. All Google Chrome installations prior to 125.0.6422.60 are affected, as are Fedora's packaged builds of Chrome/Chromium carrying the vulnerable V8 code. The vulnerability was added to CISA's KEV on 2024-05-20, has a public PoC referenced in Google's issue tracker, and public reporting ties its in-the-wild use to the North Korean Lazarus Group, which deployed the FudModule rootkit against infected Chrome users.

Do: Upgrade Google Chrome to 125.0.6422.60 or later on all endpoints, and install the updated chromium packages published for Fedora, prioritizing this patch because the flaw is CISA KEV-listed with a mandatory mitigation deadline. Because Lazarus Group is exploiting this in the wild via crafted web pages, review endpoint telemetry for suspicious browser-borne activity and warn users against opening links from untrusted or decoy game/job-lure sites.

9.615% KEV PoC
  • google chrome Google Chrome prior to 125.0.6422.60 (vulnerable V8 engine)
  • fedoraproject fedora Fedora-packaged Chromium/Chrome builds containing the vulnerable V8 (fixed via Fedora advisories; specific Fedora package versions not specified in the source d
masson the order of billions of Chrome installations (Chrome is the world's dominant desktop browser with roughly 65% market share and a multi-billion active…

Indicators of compromiseAll →

TypeIndicatorContext
domaindetankzone.comstigation traced the infection back to a deceptive website, detankzone[.]com , which posed as a legitimate decentralized finance (DeFi
Full article357 words · extracted from infosecurity-magazine.com · click to collapse

A recently discovered cyber-attack by the notorious Lazarus Group, including its BlueNoroff subgroup, has exposed a new vulnerability in Google Chrome.

The group used a zero-day exploit to take complete control of infected systems, marking the latest in a long series of sophisticated campaigns from the North Korean-backed threat actor.

The campaign was uncovered when Kaspersky Total Security detected a new instance of the Manuscrypt malware on a personal computer in Russia.

Manuscrypt, a signature Lazarus tool, has been in use since at least 2013, appearing in over 50 documented campaigns targeting governments, financial institutions, cryptocurrency platforms and more. However, this case stood out as the group rarely targets individuals directly.

Zero-Day Exploit in Google Chrome Enables Full System Control

Further investigation traced the infection back to a deceptive website, detankzone[.]com, which posed as a legitimate decentralized finance (DeFi) game platform. Visitors to the site unknowingly triggered the exploit simply by accessing it through Chrome. The game, advertised as an NFT-based multiplayer online battle arena, was merely a facade, hiding malicious code that hijacked the user's system via the browser.

The exploit, which targeted a newly introduced feature in Chrome's V8 JavaScript engine, allowed attackers to bypass the browser's security mechanisms and gain remote control over affected devices. Kaspersky researchers promptly reported the vulnerability to Google, which released a patch within two days.

Here are the key vulnerabilities at the heart of this campaign:

  • CVE-2024-4947: A flaw in Chrome's new Maglev compiler that allows attackers to overwrite critical memory structures

  • V8 Sandbox Bypass: A second vulnerability enabled Lazarus to bypass Chrome's memory protection features, executing arbitrary code

Read more on browser-focused attacks: Browser Phishing Threats Grew 198% Last Year

While Kaspersky adhered to responsible disclosure practices, Microsoft reportedly published a related report that missed the zero-day element of the campaign. This triggered Kaspersky to provide further details, emphasizing the gravity of the vulnerability and the need for users to update their browsers immediately.

As Lazarus continues to refine its methods, leveraging social engineering, zero-day exploits and legitimate-looking platforms, organizations and individuals alike must remain vigilant.

Image credit: Alberto Garcia Guillen / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/lazarus-group-exploits-google/