North Korean hacker targets crypto users through Chromium vulnerability

user avatar

by Giorgi Kostiuk

2 years ago

Made with AI


  1. Citrine Sleet and its methods
  2. The hacker and Chromium vulnerability
  3. Microsoft's precautionary measures

  4. Tech giant Microsoft recently warned about a North Korean threat actor exploiting a zero-day vulnerability in Google’s Chromium to gain remote code execution to steal crypto assets from unsuspecting users.

    Citrine Sleet and its methods

    Tracked by Microsoft as Citrine Sleet, the threat actor is believed to have conducted extensive reconnaissance of the crypto industry and specializes in targeting institutions or individuals managing digital assets using the unique trojan malware it developed, AppleJeus. Other security firms track the threat actor as Hidden Cobra, Labyrinth Chollima, UNC4736, and AppleJeus.

    The hacker and Chromium vulnerability

    In a recent blog post, Microsoft said Citrine Sleet often leverages social engineering tactics to trick users into downloading malicious software, which gathers information necessary to seize control of the target’s digital assets.

    "The threat actor creates fake websites masquerading as legitimate cryptocurrency trading platforms and uses them to distribute fake job applications or lure targets into downloading a weaponized cryptocurrency wallet or trading application based on legitimate applications." The post read.

    Microsoft's precautionary measures

    Microsoft tied Citrine Sleet to a zero-day vulnerability hack in Chromium on August 19 after observing a malicious rootkit attributed to Diamond Sleet deployed by the threat actor. Diamond Sleet is another North Korean actor believed to be sharing hacking tools and infrastructure with Citrine Sleet.

    Per the post, Google patched the vulnerability on August 21 and urged users to implement the fixes as soon as possible. Microsoft said it directly notified targeted or compromised customers and provided them with critical information to secure their environments.

    Microsoft continues to enhance security measures and inform users about new threats to prevent further attacks on digital assets.

Tier I

Sector: #18291

Sealed Hiding Place Room

Resource Cache

Resource Cache

Tier I

Requires 25% Tier Progress to Claim
Meme Cache

Meme Cache

Tier I

Requires 50% Tier Progress to Claim
Equipment Cache

Equipment Cache

Tier I

Requires 75% Tier Progress to Claim

After collecting, hiding places will be stored in your inventory and can be opened with Keys.

Other news

TRON DAO Takes Center Stage at TOKEN2049 and DAS Asia 2026

TRON DAO participated as Title Sponsor at TOKEN2049 Singapore and DAS Asia 2026, discussing the future of stablecoins, AI-driven commerce, and blockchain infrastructure.

user avatarKofi Adjeman

Bitcoin Life Insurance Company Secures $375 Million in Funding

A Bermuda-based life insurance company operating entirely in Bitcoin has raised $375 million to meet growing demand for its policies among wealthy families.

user avatarNguyen Van Long

Senator Blumenthal Seeks Information from Cantor Fitzgerald on Tether Dealings

Senator Richard Blumenthal has requested Cantor Fitzgerald to provide records related to its business relationship with Tether, focusing on the financial gains of Commerce Secretary Howard Lutnick's family.

user avatarSatoshi Nakamura

Ledger Halts Sales Amid Fund Loss Investigations

Ledger has paused sales and shipments of its hardware wallets after reports of fund losses from customers in Southeast Asia who purchased devices from CryptoBilis.

user avatarJesper Sørensen

Project Eleven and Quantus Collaborate on Strongpoint for Future Crypto Custody

Project Eleven has partnered with Quantus to enhance crypto custody solutions through the integration of the Quantus Network into Strongpoint, targeting support for post-quantum cryptography by Q1 2027.

user avatarRajesh Kumar

Sui and Alibaba Cloud Collaborate on AI Agent Payment Integration

Sui and Alibaba Cloud are developing a payment model for AI agents to autonomously pay for cloud services using stablecoins.

user avatarLucas Weissmann

Important disclaimer: The information presented on the Dapp.Expert portal is intended solely for informational purposes and does not constitute an investment recommendation or a guide to action in the field of cryptocurrencies. The Dapp.Expert team is not responsible for any potential losses or missed profits associated with the use of materials published on the site. Before making investment decisions in cryptocurrencies, we recommend consulting a qualified financial advisor.