HomeSecurityLazarus exploits zero-day in Chrome for attacks

Lazarus exploits zero-day in Chrome for attacks

The North Korean hacking group Lazarus exploited a Google Chrome zero-day tracked as CVE-2024-4947 through a fake decentralized finance ( DeFi ) game targeting individuals in the cryptocurrency space.

See also: North Korean hackers Andariel attacks are financially motivated

Lazarus Chrome zero-day

Kaspersky discovered the attacks on May 13, 2024, and reported the Chrome zero-day flaw to Google. Google released a fix for CVE-2024-4947 on May 25, with Chrome version 125.0.6422.60/.61

Kaspersky discovered the campaign, which began in February 2024, after detecting a new variant of the “Manuscrypt” malware on the personal computer of one of its customers in Russia. Lazarus has been using Manuscrypt for years, but researchers were struck by the group’s atypical targeting scope, which seemingly included random individuals.

Further telemetry showed that Google Chrome had been exploited prior to the detection of the new Manuscrypt payload, with the exploit originating from the website “detankzone[.]com.” This website promoted a tank-themed NFT-based multiplayer online battle arena (MOBA) game called DeTankZone.

Lazarus promoted the game largely through advertising campaigns on social media platforms such as X, spear-phishing emails, and premium LinkedIn accounts used in direct attacks on high-value targets.

While downloading and committing the game's mechanics, Kaspersky discovered that the game was based on stolen source code from a legitimate game called DeFiTankLand, which Lazarus had simply renamed for its own purposes.

See also: Are you a programmer? Beware! The Lazarus hacking gang uses fake coding tests to distribute malware

Lazarus exploits zero-day in Chrome for attacks

The Lazarus exploit script corrupted Chrome's memory by exploiting the application's JIT compiler, Maglev, replacing sections that ultimately gave them access to the entire address space of the Chrome process. At this stage, attackers could access cookies, authentication tokens, saved passwords, and browsing history.

Chrome's V8 Sandbox isolates JavaScript execution from the rest of the system, so Lazarus used a second Chrome zero-day in V8 to circumvent it and achieve remote code execution by running shellcode in system memory.

The shellcode used by Lazarus serves as a reconnaissance tool, helping attackers determine whether the compromised machine is valuable enough to continue the attack. It collected CPU, BIOS, and OS information, performed anti-VM and anti-debugging checks, and sent the information to Lazarus' command and control (C2) server.

See also: Russian arrested for money laundering – He was helping the Lazarus hackers

The Lazarus hacking group is one of the most notorious and dangerous cybercriminal groups in the world. They originate from North Korea and are known for their attacks on large organizations and government agencies worldwide. Their activities range from stealing sensitive data to financial fraud, and they use advanced techniques to penetrate security systems. The Lazarus group has been involved in many high-profile attacks, such as the infamous Sony Pictures network breach in 2014 and ransomware attacks such as WannaCry in 2017.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS