25/10/2024 Lazarus Group exploited Chrome vulnerability with fake NFT game

The North Koreans invested great effort in creating and promoting a game that apparently drained users’ wallets.

Lazarus Group exploited Chrome vulnerability with fake NFT game

The North Koreans invested great effort in creating and promoting a game that apparently drained users’ wallets.

The North Korean Lazarus Group of hackers used a fake blockchain-based game to exploit a zero-day vulnerability in Google’s Chrome browser and install spyware that stole wallet credentials. Kaspersky Labs analysts noticed the exploit in May and reported it to Google, which has fixed it.

Play at a big risk

The hacker’s play-to-earn multiplayer online battle arena game was fully playable and had been promoted on LinkedIn and X. The game was called DeTankZone or DeTankWar and used non-fungible tokens (NFTs) as tanks in a worldwide competition.

Users were infected from the website, even if they did not download the game. The hackers modeled the game on the existing DeFiTankLand.

The hackersusedmalware called Manuscrypt followed by a previously unknown “type confusion bug in the V8 JavaScript engine.” It was the seventh zero-day vulnerability found in Chrome in 2024 through mid-May.

Kaspersky principal security expert Boris Larin said:

“The significant effort invested in this campaign suggests they had ambitious plans, and the actual impact could be much broader, potentially affecting users and businesses worldwide.”

The fake game wasnoticedby Microsoft Security in February, though the hackers removed the exploit from the website before Kaspersky could analyze it. The lab informed Google of it anyway and Google fixed the vulnerability in Chrome before the hackers could use it again.

Screenshot from Lazarus Group’s fake game. Source:SecureList

North Korea loves crypto

Zero-day vulnerabilities take the vendor by surprise and there is no ready patch for them. It took Google 12 days to patch the vulnerability in question.

Another North Korean hacker group harnessed a different zero-day vulnerability in Chrome to target crypto holders earlier this year.

Source:Microsoft Threat Intelligence

Lazarus Group is fond of crypto. Between 2020 and 2023, itlaundered over $200 millionin crypto from 25 hacks, according to crypto crime watcher ZachXBT.

The United States Treasury Department also alleged Lazarus Groupto be behind the attack onRonin Bridge that netted crypto worth over $600 million in 2022.

US cybersecurity firm Recorded Future found that North Korean hackers as a wholestole over $3 billion in crypto between 2017 and 2023.

Arts

https://cointelegraph.com/news/north-korean-lazarus-group-chrome-zero-day-nft-game-hack

Interesting NFTs
Not many like me at all!
Yo! I'm Not many like me at all!. I'm a professional Ventriloquist and I love lasagna. My great-great-great-great-great-great grandkitty lived with King Henry VIII. I think you'll love me beclaws I have cattitude.
Block Chain Dungeon
Once upon a time... a little boy named Leo loved to paint, draw and experiment. He also loved to play with blocks and chains, which drew him again and again into the rooms of his friends Michel and Angelo. Often they also met in virtual rooms of Cryptovoxels, Decentraland, Somnium Space or Sandbox to create new inventions, read books about new technologies, or just swing the brushes. But on this day something gigantic happened. A good friend of Leo came to visit and brought his girlfriend Mona, who wanted a piece of Leo's art on her skin. This was the birth of the NFT's, as Leo developed Non Fungible Tattoos in the Block Chain Dungeon of Michel and Angelo. From that day on people from all over the world came to get NFT's from Leo or one of his students, like "Skeenee the rat", who controls the NFT machine with his laptop. A new age began.
The Switch
The Switch is a unique, “one of one” NFT that demonstrates the evolution of artwork in the digital realm. The Switch is developed to change form at a specific point of time in the future, known by Pak. The evolution is determined and rendered immutable by smart contracts, or self-executing code on the Ethereum blockchain.
ˈSÄ-V(Ə-)RƏN-TĒ
"I'm not smart enough to be an astronaut." That is what 7 year old Rayden told Micah the first time they met. How can a 7-year-old already feel limitations on his dreams? For centuries, the black community has been the target of a system designed to limit their power, their earning potential, their dreams. Now is your opportunity to help destroy the system. For the next 11 years, on each brother's birthday, (Rayden, Aug. 10/ Jacque Nov. 6), you the viewer, will be able to directly contribute Bitcoin to a wallet that will be given to each child upon turning 18. In what is one of the most powerful use cases for Bitcoin, 100% of your contributions and earnings will open all new doors for these special young men.
#95342
By OthersideDeployer