• Dapps:16.23K
  • Blockchains:78
  • Active users:66.47M
  • 30d volume:$303.26B
  • 30d transactions:$879.24M

North Korean hacker targets crypto users through Chromium vulnerability

user avatar

by Giorgi Kostiuk

a year ago


  1. Citrine Sleet and its methods
  2. The hacker and Chromium vulnerability
  3. Microsoft's precautionary measures

  4. Tech giant Microsoft recently warned about a North Korean threat actor exploiting a zero-day vulnerability in Google’s Chromium to gain remote code execution to steal crypto assets from unsuspecting users.

    Citrine Sleet and its methods

    Tracked by Microsoft as Citrine Sleet, the threat actor is believed to have conducted extensive reconnaissance of the crypto industry and specializes in targeting institutions or individuals managing digital assets using the unique trojan malware it developed, AppleJeus. Other security firms track the threat actor as Hidden Cobra, Labyrinth Chollima, UNC4736, and AppleJeus.

    The hacker and Chromium vulnerability

    In a recent blog post, Microsoft said Citrine Sleet often leverages social engineering tactics to trick users into downloading malicious software, which gathers information necessary to seize control of the target’s digital assets.

    "The threat actor creates fake websites masquerading as legitimate cryptocurrency trading platforms and uses them to distribute fake job applications or lure targets into downloading a weaponized cryptocurrency wallet or trading application based on legitimate applications." The post read.

    Microsoft's precautionary measures

    Microsoft tied Citrine Sleet to a zero-day vulnerability hack in Chromium on August 19 after observing a malicious rootkit attributed to Diamond Sleet deployed by the threat actor. Diamond Sleet is another North Korean actor believed to be sharing hacking tools and infrastructure with Citrine Sleet.

    Per the post, Google patched the vulnerability on August 21 and urged users to implement the fixes as soon as possible. Microsoft said it directly notified targeted or compromised customers and provided them with critical information to secure their environments.

    Microsoft continues to enhance security measures and inform users about new threats to prevent further attacks on digital assets.

0

Rewards

chest
chest
chest
chest

More rewards

Discover enhanced rewards on our social media.

chest

Other news

Whale Withdraws 6 Million Worth of SOL from OKX and Stakes It

chest

A cryptocurrency whale withdrew 48,744 SOL from OKX, valued at 615 million, and staked the assets despite an unrealized loss of 304 million.

user avatarFilippo Romano

Do Kwon Sentenced to 15 Years, Faces Possible Extradition to South Korea

chest

Do Kwon, founder of Terraform Labs, sentenced to 15 years in prison for conspiracy to defraud and wire fraud, with potential extradition to South Korea for further charges.

user avatarTomas Novak

Terraform Labs Files $4 Billion Lawsuit Against Jump Trading.

chest

Terraform Labs has filed a $4 billion lawsuit against Jump Trading for alleged market manipulation and asset misuse.

user avatarEmily Carter

Solana Price Shows Signs of Recovery Amid Market Concerns

chest

The Solana price has increased by 6% on Friday, approaching the 126 mark after a concerning dip below 120. This recovery is influenced by proactive measures from the Solana Foundation and a significant investment from Mangoceuticals. However, experts caution that the price is still in a downtrend.

user avatarKaterina Papadopoulou

XRP's Long-Term Price Outlook: Potential to Reach $10 by 2030

chest

XRP's price trajectory from 2026 to 2030 could reach between $5 and $10, depending on macroeconomic factors and adoption metrics.

user avatarMaya Lundqvist

Ethereum Price Response to High-Profile Transactions

chest

Hayes' transfer of 680 ETH is part of a historical pattern that has influenced market perceptions and price fluctuations.

user avatarLeo van der Veen

Important disclaimer: The information presented on the Dapp.Expert portal is intended solely for informational purposes and does not constitute an investment recommendation or a guide to action in the field of cryptocurrencies. The Dapp.Expert team is not responsible for any potential losses or missed profits associated with the use of materials published on the site. Before making investment decisions in cryptocurrencies, we recommend consulting a qualified financial advisor.