The North Korean threat actor known as the Lazarus Group has been linked to the exploitation of a zero-day vulnerability in Google Chrome, now patched, allowing them control over compromised devices.
Kaspersky researchers discovered this attack chain in May 2024, which targeted a Russian national’s PC using the Manuscrypt backdoor. The attack involved luring users to a fraudulent gaming website, detankzone[.]com, which launched a zero-day exploit on Chrome when visited. This website, designed to appear as a professional product page for an NFT-based online tank game, was actually a front for delivering malicious code.
“This website looked like a well-crafted page for a decentralized finance (DeFi) NFT-based tank game and invited users to try a demo version,” explained Kaspersky researchers Boris Larin and Vasily Berdnikov. “However, it had hidden code that exploited a Chrome vulnerability, enabling full control over the victim's PC.”
The vulnerability exploited, CVE-2024-4947, is a type confusion bug within Chrome’s V8 JavaScript and WebAssembly engine. Google addressed this flaw in May 2024. Lazarus’s campaign, which began around February 2024, used the fake game as malware delivery, a tactic Microsoft has attributed to Moonstone Sleet, another North Korean hacking group.
Attackers initiated contact with targets via email or messaging platforms, posing as blockchain companies or game developers seeking investments. The zero-day exploit chain leveraged two vulnerabilities: one granted read/write access to Chrome’s address space, while another bypassed the V8 sandbox.
This V8 sandbox bypass, patched in March 2024, allowed attackers to access memory outside of the register array, a critical vulnerability potentially known to the attackers before the patch.
Upon a successful breach, Lazarus ran shellcode that gathered system data to evaluate the device’s worth for further exploitation. Kaspersky noted Lazarus’s skillful social engineering: “The effort Lazarus APT invests into social engineering is remarkable,” referring to their months-long campaign, building social media presence, and promoting the fake game on X (formerly Twitter) using generative AI content and graphics.
These campaigns utilized X and LinkedIn, as well as targeted websites and spear-phishing tactics, to reach prominent figures in the cryptocurrency industry. The website also contained a ZIP download (“detankzone.zip”) with a disguised game that required registration, while covertly installing a loader known as YouieLoad.
It’s suspected that Lazarus may have stolen the source code for this game from the legitimate play-to-earn blockchain game DeFiTankLand (DFTL), hacked in March 2024, leading to a loss of $20,000 worth of DFTL2 coins. The Lazarus Group may have exploited this breach, repurposing the game code to advance their own schemes.
“Lazarus is one of the most persistent and financially motivated APT groups,” Kaspersky researchers noted, emphasizing that their tactics constantly evolve. The group has integrated generative AI into their toolkit, suggesting they’re poised to develop even more sophisticated social engineering schemes in the future.