COINTURK NEWSCOINTURK NEWSCOINTURK NEWS
  • Real-Time News Feed
  • Bitcoin
  • Altcoin
  • Ethereum
  • Technology News
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Search
© 2024 COINTURK NEWS. All Rights Reserved.
Reading: Google Chrome Patch Addresses North Korean Exploit Targeting Crypto Investors
Share
Languages
  • TürkçeTürkçe
  • EspañolEspañol
Font ResizerAa
COINTURK NEWSCOINTURK NEWS
Font ResizerAa
Search
  • Real-Time News Feed
  • Bitcoin
  • Altcoin
  • Ethereum
  • Technology News
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Follow US
© 2025 BLOCKCHAIN Information Technologies. >> COINTURK NEWS
Powered by LK SOFTWARE
COINTURK NEWS > Cryptocurrency Security > Google Chrome Patch Addresses North Korean Exploit Targeting Crypto Investors
Cryptocurrency Security

Google Chrome Patch Addresses North Korean Exploit Targeting Crypto Investors

In Brief

  • Microsoft identified a zero-day vulnerability in Chromium exploited by North Korean attackers.

  • The exploit targeted crypto investors for financial gain.

  • Google Chrome patched the vulnerability on August 21, 2024.

COINTURK NEWS
COINTURK NEWS 9 months ago
Share
SHARE

Recently, we mentioned the discovery of a new 0day vulnerability in Google Chrome. 0day or zero-day vulnerabilities are “elite” flaws used by a small number of highly skilled attackers. They are usually sold on the deep web for thousands or even tens of thousands of dollars. Those who discover them often use them exclusively to gain larger rewards.

Chrome Vulnerability and Crypto

We always advise staying away from untrusted websites and applications. It is also recommended to use proven paid antivirus software to secure your web traffic. While antivirus software does not always protect users, it significantly keeps you away from known traps.

Microsoft recently reported that the security vulnerability we mentioned earlier was used by North Korean attackers to target crypto investors.

“On August 19, 2024, Microsoft identified that a North Korean threat actor exploited a zero-day vulnerability in Chromium, identified as CVE-2024-7971, to achieve remote code execution (RCE). We assess with high confidence that the observed exploitation of CVE-2024-7971 can be attributed to a North Korean threat actor targeting the cryptocurrency sector for financial gain.”

Microsoft experts found that the vulnerability was jointly used by two groups named Diamond Sleet and Citrine Sleet. So, what is the attack scenario? We see this in the details of the investigation.

“The observed zero-day exploit attack by Citrine Sleet used typical stages seen in browser exploit chains. Initially, targets were redirected to the attack address voy****club[.]space controlled by Citrine Sleet. Although we cannot currently verify how targets were redirected, social engineering (directing to a link by saying trade or crypto wallet application, etc.) is a common tactic used by Citrine Sleet. When a target connected to the internet address, the zero-day RCE exploit for CVE-2024-7971 was delivered.

After the RCE exploit succeeded in executing code in the protected Chromium renderer process, shellcode containing a Windows sandbox escape exploit and FudModule rootkit was downloaded and then loaded into memory. The sandbox escape exploited a security vulnerability in the Windows kernel, CVE-38106, which Microsoft fixed on August 13, 2024, before discovering this activity by the North Korean threat actor.”

Google Chrome patched this vulnerability on August 21 and is expected to provide a detailed explanation within 60 days. Always keep your browser updated and stay vigilant. North Korean attackers are now conducting much more targeted attacks, and such newly discovered vulnerabilities make their job easier. No comprehensive report has yet been published on the crypto investors victimized by this vulnerability. Additionally, those who have not yet updated their systems remain potential targets.

You can follow our news on Telegram, Facebook, Twitter & Coinmarketcap
Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.

You Might Also Like

Meta Takes Action to Combat Rising Fraud on Social Media Platforms

The Shocking Story of How an X Account Hack Sent Bitcoin Prices Soaring

Protect Your Cryptocurrency: Strengthen Your Online Security with CZ’s Tips!

Lido Swiftly Secures Its Network After Critical Oracle Breach

Crypto Market Faces Severe Security Breaches in April

COINTURK NEWS 30 August, 2024 - 8:42 pm 30 August, 2024 - 8:42 pm
Share This Article
Facebook Twitter
Share
Previous Article Analyst Identifies Bitcoin Price Levels Amid Market Decline
Next Article Investors Show Weak Appetite for Meme Coins
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Stay Connected

8.1k Like
21.1k Follow
1.1k Follow

Latest News

Hong Kong Police Nabs 12 in Bold Crypto Money Laundering Crackdown
Cryptocurrency News
Scientists Challenge Gold’s Significance with Lead-to-Gold Transformation
Bitcoin News
Tom Lee Predicts a Bullish 2026 for U.S. Stock Markets
Cryptocurrency News
Solana Excels in Rising Market with Innovative Blockchain
Solana (SOL)
//

COINTURK was launched in March 2014 by a group of technology enthusiasts who believe that Bitcoin will be as important as the internet in the world of the future thanks to the amazing technology underlying it.

CRYPTOCURRENCY LIVE PRICES

  • Bitcoin (BTC) Live Price
  • Ethereum (ETH) Live Price
  • Ripple (XRP) Live Price
  • Solana (SOL) Live Price
  • Dogecoin (DOGE) Live Price
  • Cardano (ADA) Live Price
  • Chainlink (LINK) Live Price

OUR PARTNERS

  • COINMARKETCAP
  • COINGECKO
  • BITCOINHABER
  • BH NEWS
  • 21MILYON
  • NEWSLINKER

OUR COMPANY

  • About Us
  • Cookie Policy
  • Advertising
  • Contact
COINTURK NEWSCOINTURK NEWS
Follow US
© 2025 BLOCKCHAIN Information Technologies. >> COINTURK NEWS
Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Lost your password?