Lazarus Group Unleashes Blockchain Game To Exploit Chrome And Steal Crypto

2024-10-25 08:30

A cybersecurity firm yesterday reported that a group of notorious hackers from North Korea was able to steal $3 billion worth of cryptocurrency from users by devising a fake blockchain game. Kaspersky Lab said that the Lazarus Group took advantage of a key vulnerability in the Google Chrome browser that allowed them to drain the crypto wallets of their victims.

Lazarus Group: $3 Billion Crypto Heist

It was reported that the North Korean hackers used the fake game to steal more than $3 billion in cryptocurrency — an operation the group successfully conducted within a six-year period, from 2016 to 2022.

The heist is the adverse consequence of Google’s failure to patch a vulnerability in the Chrome browser.

Meanwhile, a blockchain detective conducting a separate investigation found that the Lazarus Group executed 25 hacking attacks, laundering $200 million worth of crypto.

It also uncovered the existence of a network of developers in North Korea that works for “established” cryptocurrency projects. The network allegedly gets a monthly paycheck of $500,000.

The Dubious Game Plan

Vasily Berdnikov and Boris Larin, analysts of Kaspersky Labs, said that the Lazarus Group created a fake game called DeTankZone or DeTankWar that revolves around Non-Fungible Tokens (NFTs) to siphon the crypto wallets of their victims.

The analysts revealed that the hackers made use of the zero-day vulnerability in the Chrome browser in their unscrupulous act.

Berdnikov and Larin explained that hackers used the fake game to persuade their victims and led them to a malicious website, which inject malware into their computers called Manuscript.

With the use of Manuscript, the hackers were able to corrupt Chrome’s memory, allowing them to obtain users’ passwords, authentication tokens, and everything they needed to steal the crypto of their unwitting victims.

12 Days To Solve The Issue

Kaspersky Lab analysts discovered what the Lazarus Group was doing in May. Berdnikov and Larin immediately relayed to Google the issue so the platform could fix the vulnerability.

However, Google was unprepared to address the zero-day vulnerability issue, taking them 12 days to fix the vulnerability.

Boris Larin, a principal security expert from Kaspersky Lab, said that the notable effort invested by the hacker group in the said hacking campaign indicates that the group has an ambitious plan.

Larin noted that what the group has done might have broader impact than previously thought.

The Lazarus Group is a reminder that the battle against hackers continues. Chrome’s vulnerabilities emphasized that platforms should always ensure that their security measures are updated and be vigilant of cybersecurity threats.

Featured image from Le Parisien, chart from TradingView

Similar to Notcoin - Blum - Airdrops In 2024

origin »

Trident Group (TRDT) на Currencies.ru

$ 0.0132492 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 42.85 %
Cегодня L: $0.0132492 - H: $0.0132492
Капитализация $16.072k Rank 99999
Доступно / Всего 1.213m TRDT

group steal chrome lazarus blockchain game took

group steal → Результатов: 45


North Korean Hackers Pose As VC Firms And Banks To Steal Millions From Crypto Startups

North Korean hackers are taking it a notch higher by pretending to be venture capitalists to steal from cryptocurrency startups. BlueNoroff, the name given by cybersecurity experts to a crew associated with the North Korean government-funded hacking operation Lazarus Group, has expanded its target list to include venture capital firms, cryptocurrency startups, and banks, a report by cybersecurity […]

2022-12-29 13:39


CryptoSlate Wrapped Daily: Binance looking to spend $1B on deals in 2022; 2 million BNB stolen in BSC bridge hack

The biggest news in the cryptosphere for October7 includes Binance fixing the BSC bridge exploit after 2 million BNB were stolen, Bitcoin’s sinking following new United States payroll data, and the second group of attackers taking advantage of the BSC bridge exploit to steal over 60 ETH from Binance by creating a coin.

2022-10-8 00:21


Kaspersky: Lazarus Hackers To Steal Crypto Using Telegram in ‘Operation AppleJesus Sequel’

The Moscow-based cybersecurity firm Kaspersky has informed cryptocurrency users that North Korean hackers have developed new ways of delivering malware through Telegram. Kaspersky has been looking at the latest attacks of the Lazarus Group, a North Korea-related cybercrime organization that has also conducted the AppleJesus attack on some of the most important crypto exchanges in […]

2020-1-10 22:16


Фото:

MasterMana Botnet takes over your machine to empty your cryptocurrency wallet

Cybersecurity researchers have detailed a dangerous botnet specifically targeting businesses to steal sensitive data and cryptocurrency. Dubbed “MasterMana Botnet,” the ongoing campaign is believed to be connected to the “Gorgon Group,” a crew of cyberbaddies linked to worldwide criminal activity and repeated attacks on governments.

2019-10-2 19:57


Фото:

Lads allegedly beat up their ‘friend’ to steal his Bitcoin

A cohort of young men have been accused of drunkenly assaulting their “friend” to extort the credentials to his cryptocurrency wallet, the New York Post reports. According to the report, the attackers demanded the victim “provide […] login information for his cryptocurrency accounts while holding his head underwater in the bathtub, punching him in the stomach, and throwing hot wax on him.

2018-11-7 16:56