25/10/2024 Lazarus Group exploited Chrome vulnerability with fake NFT game

The North Koreans invested great effort in creating and promoting a game that apparently drained users’ wallets.

Lazarus Group exploited Chrome vulnerability with fake NFT game

The North Koreans invested great effort in creating and promoting a game that apparently drained users’ wallets.

The North Korean Lazarus Group of hackers used a fake blockchain-based game to exploit a zero-day vulnerability in Google’s Chrome browser and install spyware that stole wallet credentials. Kaspersky Labs analysts noticed the exploit in May and reported it to Google, which has fixed it.

Play at a big risk

The hacker’s play-to-earn multiplayer online battle arena game was fully playable and had been promoted on LinkedIn and X. The game was called DeTankZone or DeTankWar and used non-fungible tokens (NFTs) as tanks in a worldwide competition.

Users were infected from the website, even if they did not download the game. The hackers modeled the game on the existing DeFiTankLand.

The hackersusedmalware called Manuscrypt followed by a previously unknown “type confusion bug in the V8 JavaScript engine.” It was the seventh zero-day vulnerability found in Chrome in 2024 through mid-May.

Kaspersky principal security expert Boris Larin said:

“The significant effort invested in this campaign suggests they had ambitious plans, and the actual impact could be much broader, potentially affecting users and businesses worldwide.”

The fake game wasnoticedby Microsoft Security in February, though the hackers removed the exploit from the website before Kaspersky could analyze it. The lab informed Google of it anyway and Google fixed the vulnerability in Chrome before the hackers could use it again.

Screenshot from Lazarus Group’s fake game. Source:SecureList

North Korea loves crypto

Zero-day vulnerabilities take the vendor by surprise and there is no ready patch for them. It took Google 12 days to patch the vulnerability in question.

Another North Korean hacker group harnessed a different zero-day vulnerability in Chrome to target crypto holders earlier this year.

Source:Microsoft Threat Intelligence

Lazarus Group is fond of crypto. Between 2020 and 2023, itlaundered over $200 millionin crypto from 25 hacks, according to crypto crime watcher ZachXBT.

The United States Treasury Department also alleged Lazarus Groupto be behind the attack onRonin Bridge that netted crypto worth over $600 million in 2022.

US cybersecurity firm Recorded Future found that North Korean hackers as a wholestole over $3 billion in crypto between 2017 and 2023.

Arts

https://cointelegraph.com/news/north-korean-lazarus-group-chrome-zero-day-nft-game-hack

Interesting NFTs
Michael Jordan - Crown Collection
“All you needed was one little match to start that whole fire.”- Michael Jordan. In regards to both the action on the court and everything that happened off of it, Jordan provided a spark that changed the future in so many different ways throughout his tenure in Chicago, and even decades after the fact. And, in the end, he got everything that he wanted when he began his NBA journey: he turned the team and organization as a whole into a respected program, like the dynasties he looked up to as a child. Having steered the Chicago Bulls to an incredible six championship rings in eight years from 1991-1998, scooping up five MVP awards in the process, Jordan is one of just a handful of superstars who have truly transcended their sports. Jordan and Scottie Pippen’s (right) relationship both on and off the pitch was arguably the foundation of the Bulls’ incredible success. Scottie Pippen was present with Jordan for all six championships in eight seasons. Dennis Rodman (left) His relentless and smart play perfectly suited what Jordan and Jackson wanted to do to take the Bulls to greater heights. Although his exploits off the court earned him special fame, Rodman was unquestionably one of the greatest basketball players of his generation and one of the finest defensive players in the history of the game.
CryptoPunk #8857
The CryptoPunks are 10,000 uniquely generated characters. No two are exactly alike, and each one of them can be officially owned by a single person on the Ethereum blockchain. Originally, they could be claimed for free by anybody with an Ethereum wallet, but all 10,000 were quickly claimed. Now they must be purchased from someone via the marketplace that's also embedded in the blockchain.
CryptoKitties
Yo! I'm Kitty #450305. I believe the world is flat. I'm often described as preposterous, and I own it. We're so fur-tunate to have found each other!
Last Selfie #7/10
Was it worth it?
#88183
By OthersideDeployer