

Lazarus Group Used Fake Blockchain Game to Exploit Zero-Day Vulnerability in Google Chrome
The North Korean Lazarus Group of hackers used a fake blockchain-based game to exploit a zero-day vulnerability in Google’s Chrome browser and install spyware
North Korean Lazarus Group hackers have exploited a zero-day vulnerability in Google Chrome to install spyware that steals wallet credentials, using a fake blockchain-based game to carry out the attack.
The Lazarus Group’s activities were detected by Kaspersky Labs analysts in May, who reported the exploit to Google. The vulnerability has since been fixed by Google.
Playing at a high risk
The hackers’ game, which was fully playable, was promoted on LinkedIn and X. It was called DeTankZone or DeTankWar and featured tanks represented by non-fungible tokens (NFTs) that competed in a global tournament.
Interestingly, users could get infected from the game’s website even without downloading the game itself. The hackers reportedly modeled the game on the existing DeFiTankLand.
According to the report, the hackers deployed Manuscrypt malware, followed by a previously unseen “type confusion bug in the V8 JavaScript engine.” This marked the seventh zero-day vulnerability found in Chrome in 2024 up to mid-May.
“The fake game was noticed by Microsoft Security back in February. However, by the time Kaspersky was able to look into it, the threat actor had already removed the exploit from the website,” Boris Larin, principal security expert at Kaspersky, told Securelist.
Despite this, the lab went ahead and informed Google about the exploit, and Chrome fixed the vulnerability before the hackers could reintroduce it.
Screenshot from Lazarus Group’s fake game, as shared by SecureList
Related: FBI highlights 6 Bitcoin wallets linked to North Korea, urging crypto exchanges to be vigilant
North Korea has a thing for crypto
Zero-day vulnerabilities are those that a vendor is made aware of for the first time, without any patch being ready for it. In this case, it took Google 12 days to patch the vulnerability in question.
Earlier this year, another zero-day vulnerability in Chrome was exploited by a separate North Korean hacker group to target crypto holders.
As reported by Microsoft Threat Intelligence, Lazarus Group is known to have a strong preference for cryptocurrency. According to crypto crime watcher ZachXBT, the group laundered over $200 million in crypto from 25 hacks between 2020 and 2023.
The United States Treasury Department has also accused Lazarus Group of being behind the 2022 attack on Ronin Bridge, which resulted in the theft of crypto valued at over $600 million.
Over the seven-year period from 2017 to 2023, North Korean hackers stole a total of more than $3 billion in crypto, according to cybersecurity firm Recorded Future.
Magazine: Lazarus Group’s favorite exploit revealed — An analysis of crypto hacks by the notorious group
The above is the detailed content of Lazarus Group Used Fake Blockchain Game to Exploit Zero-Day Vulnerability in Google Chrome. For more information, please follow other related articles on the PHP Chinese website!

Robbie Mitchnick, head of digital assets at Blackrock, the world's largest asset manager, emphasized during the Token2049 crypto conference that institutional views on bitcoin could dramatically shift

We've all heard the story by now—the incredible rise of Shiba Inu. The meme coin that started as a fun, light-hearted alternative to Dogecoin became one of the most talked-about and profitable cryptocurrencies of its time.

The Solana price rebound is holding above $150 after recent losses, offering signs of recovery.

Ruvi's presale isn't just about speculating; it's about making early gains your reality. Here are examples of its incredible earning potential based on various investment levels:
![Dogecoin [DOGE] saw a 33.5% decrease in trading volume in the past 24 hours](https://img.php.cn/upload/article/001/246/273/174641630633814.jpg?x-oss-process=image/resize,p_40)
DOGE saw a 33.5% decrease in trading volume in the past 24 hours, at the time of writing. This could be a weekend effect, when trading volume tends to fall

This innovative blockchain solution is grabbing attention, offering not just token utility with cutting-edge artificial intelligence but a jaw-dropping VIP presale program

Dogecoin (DOGE) surged 2.3% over the last 24 hours to breach the $0.17 resistance amid renewed optimism around Bitcoin ETF-driven inflows.

Trying to time the crypto market can feel like chasing shadows—but when the signals line up and the volume starts flowing, it's the weekend picks that often pack the most explosive moves.

Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

Video Face Swap
Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

PhpStorm Mac version
The latest (2018.2.1) professional PHP integrated development tool

Dreamweaver CS6
Visual web development tools

Dreamweaver Mac version
Visual web development tools

VSCode Windows 64-bit Download
A free and powerful IDE editor launched by Microsoft

Atom editor mac version download
The most popular open source editor
