Stealing Cryptocurrency from Google Chrome Vulnerability

NGUYỄN ĐĂNG |

Taking advantage of a vulnerability in Google Chrome, the Lazarus hacker group attacked and installed spyware to steal victims' financial information.

This information was shared by Kaspersky's Global Research and Analysis Team (GReAT) at the Security Analyst Summit (SAS) in Bali, Indonesia recently.

Through research, cybersecurity experts discovered that the hacker group Lazarus APT Group had exploited the Manuscrypt malware, which was carried out in a sophisticated and methodical cyber attack campaign.

The attack campaign is a combination of social engineering and artificial intelligence methods, aiming to deceive cryptocurrency investors.

The Lazarus hacker group is known for its sophisticated cyberattack campaigns, often exploiting Zero-Day vulnerabilities (security vulnerabilities that have not been fixed) to attack cryptocurrency trading platforms.

The Lazarus group exploited two critical vulnerabilities in the popular Google Chrome browser. One of these security holes allows attackers to spread arbitrary malware, bypass strict security barriers, and execute malicious activities on infected devices.

Using the remaining vulnerability, the attackers created a fake website for the NFT Tanks video game, luring players into participating in global matches. To enhance the persuasiveness and effectiveness of the scam campaign, the hacker group not only focused on creating a realistic game interface but also carefully planned the promotion strategy.

They created social media accounts like X (formerly Twitter) and LinkedIn to promote the game for months, and used AI-generated images to add life and credibility, making players believe in the legitimacy of the game.

In addition, the hacker group also approached influential people in the cryptocurrency field, taking advantage of their popularity on social networks to expand the scope of the attack campaign. Not only did they use the images of these people to spread threats, they also sought to directly attack the cryptocurrency accounts of those influential individuals.

Shortly after the attackers released the fake version, the original game developer reported losing $20,000 in cryptocurrency. Notably, the fake game is almost identical to the original, with only minor changes to logo placement and image quality.

Through careful analysis of the source code, cybersecurity experts concluded that the Lazarus hacker group had invested a lot of effort to create a perfect copy.

By stealing the original source code and replacing the logo and other identifying elements, the hackers created an extremely sophisticated fake version, making it easy for users to be fooled and making this targeted attack more effective.

NGUYỄN ĐĂNG
RELATED NEWS

Many future technologies appear at Techday 2024

|

The process of creating AI models from NVIDIA's H100 GPU supercomputer, as well as many future-shaping technologies, will appear for the first time in Vietnam.

Ho Chi Minh City strengthens management to prevent illegal and violent games

|

Preventing the release of unlicensed games, games with illegal content... is one of the tasks to promote the game industry in Ho Chi Minh City.

U23 Vietnam vs U23 Korea Preview in the 3rd place match of the AFC U23 Championship

|

Football prediction U23 Vietnam vs U23 Korea in the 3rd place match of the 2026 AFC U23 Championship taking place at 10:00 PM tonight (January 23).

U23 Vietnam players and the opportunity to join the national team

|

Some U23 Vietnam players have enough capacity and desire to try their hand at the national team after the 2026 AFC U23 Championship.

Focus on implementing three strategic breakthroughs, bringing Vinh Long to rapid and sustainable development

|

The 14th National Party Congress is a major political event of the country, deciding strategic issues for the future and destiny of the nation, unleashing all resources and development motivation. To help readers have a comprehensive and objective view of the contributions of the Vinh Long Provincial Party Committee Delegation at the Congress, as well as the solutions of the Provincial Party Committee in thoroughly grasping and effectively implementing the Resolution of the 14th Party Congress, reporters of Vinh Long Newspaper and Radio, Television interviewed comrade Tran Tri Quang - Deputy Secretary of the Provincial Party Committee, Chairman of the Provincial People's Committee about the above content.

Comrade Ha Quoc Tri: shifting from "passive to proactive" inspection and supervision, not allowing serious violations to occur

|

Ladies and gentlemen! In the term of the 13th Party Congress, the work of inspection, supervision, and Party discipline has achieved many important results; focusing on inspecting party members and Party organizations when there are signs of violations, thereby detecting, rectifying and handling them promptly. However, according to assessments, inspection and supervision work is still passive (i.e., inspection and supervision are only carried out when there are signs of violations).

Ha Long canned food explains the destruction of more than 130 tons of diseased meat and temporary suspension of production

|

Ha Long canned goods said they have destroyed more than 130 tons of raw materials positive for the virus, not put into production, not supplied to the market.

Preserving hundreds of ancient agarwood trees, people decide not to sell even at high prices

|

Ha Tinh - In Phuc Trach commune, hundreds of ancient agarwood trees have been preserved by people for many years, although some trees have been offered high prices, they have not yet been transferred.

Many future technologies appear at Techday 2024

NGUYỄN ĐĂNG |

The process of creating AI models from NVIDIA's H100 GPU supercomputer, as well as many future-shaping technologies, will appear for the first time in Vietnam.

Ho Chi Minh City strengthens management to prevent illegal and violent games

NGUYỄN ĐĂNG |

Preventing the release of unlicensed games, games with illegal content... is one of the tasks to promote the game industry in Ho Chi Minh City.

Google Chrome cập nhật các biện pháp bảo vệ người dùng

THU UYÊN (THEO how to geek) |

Google Chrome hiện đang cập nhật thêm các biện pháp bảo mật để bảo vệ người dùng.