NewsBytes Stage
    Hindi
    More
    In the news
    Narendra Modi
    Amit Shah
    Box Office Collection
    Bharatiya Janata Party (BJP)
    OTT releases
    Hindi
    NewsBytes Stage
    India
    Business
    World
    Politics
    Sports
    Technology
    Entertainment
    Auto
    Lifestyle
    Career
    Visual Stories
    Find Cricket Statistics

    Download Android App

    Follow us on
    • Facebook
    • Twitter
    • Linkedin
    Home / News / Technology News / North Korean hackers exploit Chrome bug to steal cryptocurrency
    Summarize
    Next Article
    North Korean hackers exploit Chrome bug to steal cryptocurrency
    Hackers exploited a vulnerability in Chromium, the underlying code for Chrome and other popular browsers

    North Korean hackers exploit Chrome bug to steal cryptocurrency

    By Mudit Dube
    Aug 31, 2024
    03:26 pm

    What's the story

    In a recent cybersecurity breach, a North Korean hacking group known as 'Citrine Sleet' exploited an unknown bug in Chrome-based browsers.

    Microsoft's cybersecurity researchers reported on Friday that the hackers' activities were first detected on August 19.

    The primary goal of this cyber attack was to target organizations and steal cryptocurrency, further solidifying Citrine Sleet's reputation for targeting the crypto industry.

    Technical details

    Exploited vulnerability in Chromium core engine

    The hackers exploited a vulnerability in the core engine of Chromium, the underlying code for Chrome and other popular browsers like Microsoft's Edge.

    This flaw was a zero-day, meaning Google, the software maker, was unaware of the bug and had no time to issue a fix before its exploitation.

    According to Microsoft, Google managed to patch this bug two days later on August 21.

    Microsoft has also taken steps to notify "targeted and compromised customers" about the cyber attack.

    Hacker tactics

    Citrine Sleet's modus operandi and targets

    Citrine Sleet, based in North Korea, primarily targets financial institutions, particularly those managing cryptocurrency.

    As per Microsoft, the group "has conducted extensive reconnaissance of the cryptocurrency industry and individuals associated with it," using social engineering techniques.

    They create fake websites posing as legitimate cryptocurrency trading platforms to distribute weaponized applications or lure targets into downloading a malicious cryptocurrency wallet.

    Their unique trojan malware, AppleJeus, is used to seize control of the targets' cryptocurrency assets.

    System compromise

    Hackers can gain complete control of targeted computers

    The attack initiated by the North Korean hackers begins with tricking a victim into visiting a web domain under their control.

    Exploiting another vulnerability in the Windows kernel, they install a rootkit—a type of malware that has deep access to the operating system—on the target's computer.

    Once this is accomplished, the hackers gain complete control over the compromised computer and its data.

    Facebook
    Whatsapp
    Twitter
    Linkedin
    Related News
    Latest
    Cryptocurrency
    Google
    Microsoft
    North Korea

    Latest

    Bangladesh Cricket Board pondering over Bangladesh's tour of Pakistan Bangladesh Cricket Board
    Why Virat Kohli's presence could lift India in England? Stats Virat Kohli
    Google Workspace accounts gain access to Gemini Live feature Google
    Adani Group deploys India's 1st hydrogen-powered truck in Chhattisgarh Adani Group

    Cryptocurrency

    Today's cryptocurrency prices: Check rates of Bitcoin, Ethereum, Dogecoin, Solana Bitcoin
    Biden's exit boosts Kamala Harris meme coin to record high Kamala Harris
    Telegram to launch browser with web3 support, app store Telegram
    Cryptocurrency prices today: Check rates of Bitcoin, Ethereum, BNB, Dogecoin Bitcoin

    Google

    AI Overviews in Google Search no longer consider sign-in status Google Search
    Google Drive can now save your scanned documents as JPEGs Google Drive
    Google Assistant's new UI on Android Auto resembles Apple's Siri Android Auto
    Ex-Googler's start-up is teaching AI how to smell Artificial Intelligence and Machine Learning

    Microsoft

    Microsoft says Delta ignored Nadella's help amid CrowdStrike outage Satya Nadella
    Bill Gates backs effort to standardize carbon removal methods Bill Gates
    Warning! This security flaw could compromise your Windows PC Microsoft Edge
    Apple may charge $20 monthly fee for advanced AI features Apple

    North Korea

    North Korea fires missiles, South Korea retaliates after 'territorial invasion' South Korea
    South Korea scrambles jets after detecting 180 North Korean warplanes South Korea
    North Korea fires 130 artillery shells as warning to Seoul South Korea
    North Korea confirms testing ICBM, warning to US, South Korea Kim Jong-un
    Indian Premier League (IPL) Celebrity Hollywood Bollywood UEFA Champions League Tennis Football Smartphones Cryptocurrency Upcoming Movies Premier League Cricket News Latest automobiles Latest Cars Upcoming Cars Latest Bikes Upcoming Tablets
    About Us Privacy Policy Terms & Conditions Contact Us Ethical Conduct Grievance Redressal News News Archive Topics Archive Download DevBytes Find Cricket Statistics
    Follow us on
    Facebook Twitter Linkedin
    All rights reserved © NewsBytes 2025