{"id":1640,"date":"2024-10-25T05:50:31","date_gmt":"2024-10-25T05:50:31","guid":{"rendered":"https:\/\/dogewisperer.com\/?p=1640"},"modified":"2024-10-25T05:50:31","modified_gmt":"2024-10-25T05:50:31","slug":"lazarus-group-unleashes-blockchain-game-to-exploit-chrome-and-steal-crypto","status":"publish","type":"post","link":"https:\/\/dogewisperer.com\/?p=1640","title":{"rendered":"Lazarus Group Unleashes Blockchain Game To Exploit Chrome And Steal Crypto"},"content":{"rendered":"<div>\n<p>A cybersecurity firm yesterday reported that a group of notorious hackers from North Korea was able to steal $3 billion worth of cryptocurrency from users by devising a fake blockchain game. <a href=\"https:\/\/securelist.com\/lazarus-apt-steals-crypto-with-a-tank-game\/114282\/\" target=\"_blank\" rel=\"noopener nofollow\">Kaspersky Lab said<\/a> that the Lazarus Group took advantage of a key vulnerability in the Google Chrome browser that allowed them to drain the crypto wallets of their victims.<\/p>\n<h2><strong>Lazarus Group: $3 Billion Crypto Heist<\/strong><\/h2>\n<p>It was reported that the North Korean hackers used the fake game to steal more than $3 billion in cryptocurrency \u2014 an operation the group successfully conducted within a six-year period, from 2016 to 2022.<\/p>\n<p>The heist is the adverse consequence of Google\u2019s failure to patch a vulnerability in the Chrome browser.<\/p>\n<p>Meanwhile, a blockchain detective conducting a separate investigation found that the <a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/lazarus-group-exploits-chrome-zero-day-campaign\" target=\"_blank\" rel=\"noopener nofollow\">Lazarus Group<\/a> executed 25 hacking attacks, laundering $200 million worth of crypto.<\/p>\n<p>It also uncovered the existence of a network of developers in North Korea that works for \u201cestablished\u201d cryptocurrency projects. The network allegedly gets a monthly paycheck of $500,000.<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"size-full\" src=\"https:\/\/www.tradingview.com\/x\/x3hcJ4ef\/\" width=\"1835\" height=\"883\"><\/p>\n<h2><strong>The Dubious Game Plan<\/strong><\/h2>\n<p>Vasily Berdnikov and Boris Larin, analysts of Kaspersky Labs, said that the Lazarus Group created a fake game called DeTankZone or DeTankWar that revolves around Non-Fungible Tokens (NFTs) to siphon the crypto wallets of their victims.<\/p>\n<p>The analysts revealed that the hackers made use of the zero-day <a href=\"https:\/\/www.scworld.com\/brief\/fraudulent-defi-game-leveraged-in-new-crypto-investor-targeted-lazarus-attack\" target=\"_blank\" rel=\"noopener nofollow\">vulnerability in the Chrome browser<\/a> in their unscrupulous act.<\/p>\n<p><img loading=\"lazy\" data-recalc-dims=\"1\" decoding=\"async\" class=\"aligncenter size-full wp-image-333655\" src=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2024\/10\/A_243cf1.png?resize=1024%2C540\" alt=\"\" width=\"1024\" height=\"540\" srcset=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2024\/10\/A_243cf1.png?w=1497 1497w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2024\/10\/A_243cf1.png?w=640 640w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2024\/10\/A_243cf1.png?w=768 768w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2024\/10\/A_243cf1.png?w=980 980w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2024\/10\/A_243cf1.png?w=750 750w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2024\/10\/A_243cf1.png?w=1140 1140w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\"><\/p>\n<p>Berdnikov and Larin explained that hackers used the fake game to persuade their victims and led them to a malicious website, which inject malware into their computers called Manuscript.<\/p>\n<p>With the use of Manuscript, the hackers were able to corrupt Chrome\u2019s memory, allowing them to obtain users\u2019 passwords, authentication tokens, and everything they needed to steal the crypto of their unwitting victims.<\/p>\n<p><strong>12 Days To Solve The Issue<\/strong><\/p>\n<p>Kaspersky Lab analysts discovered what the Lazarus Group was doing in May. Berdnikov and Larin immediately relayed to Google the issue so the platform could fix the vulnerability.<\/p>\n<p>However, Google was unprepared to address the zero-day vulnerability issue, taking them <a href=\"https:\/\/thehackernews.com\/2024\/10\/lazarus-group-exploits-google-chrome.html\" target=\"_blank\" rel=\"noopener nofollow\">12 days to fix the vulnerability.<\/a><\/p>\n<p>Boris Larin, a principal security expert from Kaspersky Lab, said that the notable effort invested by the hacker group in the said hacking campaign indicates that the group has an ambitious plan.<\/p>\n<p>Larin noted that what the group has done might have broader impact than previously thought.<\/p>\n<p>The Lazarus Group is a reminder that the battle against hackers continues. Chrome\u2019s vulnerabilities emphasized that platforms should always ensure that their security measures are updated and be vigilant of cybersecurity threats.<\/p>\n<p><em>Featured image from Le Parisien, chart from TradingView<\/em><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A cybersecurity firm yesterday reported that a group of notorious hackers from North Korea was able to steal $3 billion worth of cryptocurrency from users by devising a fake blockchain game. Kaspersky Lab said that the Lazarus Group took advantage of a key vulnerability in the Google Chrome browser that allowed them to drain the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"iawp_total_views":0,"footnotes":""},"categories":[2],"tags":[3,4,5],"class_list":["post-1640","post","type-post","status-publish","format-standard","hentry","category-news","tag-crypto","tag-doge","tag-news"],"_links":{"self":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/1640","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1640"}],"version-history":[{"count":0,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/1640\/revisions"}],"wp:attachment":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1640"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1640"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1640"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}