financetom
Cryptocurrency
financetom
/
Cryptocurrency
/
North Korean Hackers Used Fake NFT Game to Steal Wallet Credentials: Report
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
North Korean Hackers Used Fake NFT Game to Steal Wallet Credentials: Report
Nov 3, 2024 12:09 PM

Reports have emerged that bad actors allegedly tied to North Korea’s Lazarus Group executed a complex cyberattack that used a fake NFT-based game to exploit a zero-day vulnerability in Google Chrome.

According to the report, the vulnerability ultimately allowed the attackers to access people’s crypto wallets.

Exploiting Chrome’s Zero-Day Flaw

Kaspersky Labs security analysts Boris Larin and Vasily Berdnikov wrote that the perpetrators cloned a blockchain game called DeTankZone and promoted it as a multiplayer online battle arena (MOBA) with play-to-earn (P2E) elements.

Per the experts, they then embedded a malicious code within the game’s website, detankzone[.]com, infecting devices that interacted with it, even without any downloads.

The script exploited a critical bug in Chrome’s V8 JavaScript engine, letting it bypass sandbox protections and enabling remote code execution. This vulnerability allowed the suspected North Korean actors to install an advanced malware called Manuscrypt, which gave them control over the victims systems.

Kaspersky reported the flaw to Google upon discovering it. The tech giant then addressed the issue with a security upgrade days later. However, the hackers had already capitalized on it, suggesting a broader impact on global users and businesses.

What Larin and his security team at Kaspersky found interesting was how the attackers adopted extensive social engineering tactics. They promoted the tainted game on X and LinkedIn by engaging well-known crypto influencers to distribute AI-generated marketing material for it.

The elaborate setup also included professionally done websites and premium LinkedIn accounts, which helped create an illusion of legitimacy that attracted unsuspecting players to the game.

Lazarus Group’s Crypto Pursuits

Surprisingly, the NFT game wasn’t just a shell; it was fully functional, with gameplay elements such as logos, heads-up displays, and 3D models.

However, anyone visiting the P2E title’s malware-ridden website had their sensitive information, including wallet credentials, harvested, enabling Lazarus to execute large-scale crypto thefts.

The group has demonstrated a sustained interest in cryptocurrency over the years. In April, on-chain investigator ZachXBT connected them to more than 25 crypto hacks between 2020 and 2023, which bagged them more than $200 million.

Additionally, the U.S. Treasury Department has linked Lazarus to 2022’s infamous Ronin Bridge hack, in which they reportedly stole over $600 million in ether (ETH) and USD Coin (USDC).

Data collected by 21Shares’ parent company 21.co in September 2023 revealed that the criminal group held more than $47 million in assorted cryptocurrencies, including Bitcoin (BTC), Binance Coin (BNB), Avalanche (AVAX), and Polygon (MATIC).

In total, they are said to have stolen digital assets worth more than $3 billion between 2017 and 2023.

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Coinbase CEO Proposes Revamp of Token Listing Process
Coinbase CEO Proposes Revamp of Token Listing Process
Jan 28, 2025
Brian Armstrong, who heads the largest crypto exchange in the United States, Coinbase, has suggested a rethink of the company’s token listing process to respond to the incredibly high number of digital currencies being created every week. According to the crypto executive, approximately one million tokens are launched weekly, making it impossible to evaluate each individually. The Listing Process Usually,...
Donald Trump
Donald Trump
Jan 28, 2025
World Liberty Financial (WLF) a venture linked to Donald Trump and his family has been on an aggressive accumulation spree. In fact, the public wallet associated with WLF now holds $370.4 million in assets across 44 distinct cryptocurrencies. WLF Targets DeFi Leadership According to Santiments findings, these accumulation strategies signal its growing influence in decentralized finance (DeFi). Key holdings include...
MiCA Framework Brings 4 Leading Crypto Exchanges Under Unified EU Regulations
MiCA Framework Brings 4 Leading Crypto Exchanges Under Unified EU Regulations
Jan 28, 2025
Four leading cryptocurrency exchanges have recently secured full licenses under the European Unions Markets in Crypto-Assets Regulation (MiCA). MiCA, which became effective on December 30, 2024, provides a unified regulatory framework for crypto-asset service providers (CASPs) operating across the European Economic Area (EEA). Crypto.com announced on January 27 that its Malta entity received a MiCA license from the Malta Financial...
Ripple Secures Money Transmitter Licenses in New York and Texas, Expanding US Operations
Ripple Secures Money Transmitter Licenses in New York and Texas, Expanding US Operations
Jan 28, 2025
Digital asset infrastructure company Ripple has announced securing Money Transmitter Licenses (MTLs) in New York and Texas. With these new licenses, Ripple now holds over 50 MTLs. Both Texas and New York have strict regulatory frameworks and high compliance standards. Ripples MTL Expansion According to the official press release, Ripple Payments Money Transmitter Licenses (MTLs) allow US customers to utilize...
Copyright 2023-2025 - www.financetom.com All Rights Reserved