Security

North Korean hackers exploited Chrome zero-day to steal crypto

Comment

North Korean Supreme Leader Kim Jong Un attends a press confernce, June 19, 2024, in Pyongyang, North Korea.
Image Credits: Contributor / Getty Images

A North Korean hacking group earlier in August exploited a previously unknown bug in Chrome to target organizations with the goal of stealing cryptocurrency, according to Microsoft.

In a report published on Friday, the tech giant’s cybersecurity researchers said they first saw evidence of the hackers’ activities on August 19, and said the hackers were affiliated with a group called Citrine Sleet, which is known to target the crypto industry

According to the report, the hackers exploited a flaw in a core engine within Chromium, the underlying code of Chrome and other popular browsers, like Microsoft’s Edge. When the hackers exploited the vulnerability, it was a zero-day, meaning the software maker — in this case, Google — was unaware of the bug and as such had zero time to issue a fix prior to its exploitation. Google patched the bug two days later on August 21, according to Microsoft. 

Google’s spokesperson Scott Westover told TechCrunch that Google had no comment other than confirming that the bug was patched. 

Microsoft said it has notified “targeted and compromised customers,” but did not provide more information on who was targeted, nor how many targets and victims were targeted by this hacking campaign.

Contact Us

Do you have more information about North Korean government hackers, or other government-sponsored hacking activities? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email. You also can contact TechCrunch via SecureDrop.

When asked by TechCrunch, Chris Williams, a spokesperson for Microsoft, declined to say how many organizations or companies were affected. 

Researchers wrote that Citrine Sleet “is based in North Korea and primarily targets financial institutions, particularly organizations and individuals managing cryptocurrency, for financial gain,” and the group “has conducted extensive reconnaissance of the cryptocurrency industry and individuals associated with it” as part of its social engineering techniques. 

“The threat actor creates fake websites masquerading as legitimate cryptocurrency trading platforms and uses them to distribute fake job applications or lure targets into downloading a weaponized cryptocurrency wallet or trading application based on legitimate applications,” reads the report. “Citrine Sleet most commonly infects targets with the unique trojan malware it developed, AppleJeus, which collects information necessary to seize control of the targets’ cryptocurrency assets.”

The North Korean hackers’ attack started by tricking a victim into visiting a web domain under the hackers’ control. Then, because of another vulnerability in the Windows kernel, the hackers were able to install a rootkit — a type of malware that has deep access to the operating system — on the target’s computer, according to Microsoft’s report. 

At that point, it’s basically game over for the targeted victim’s data, as the hackers had gained complete control of the hacked computer. 

Crypto has been a juicy target for North Korean government hackers for years. A United Nations Security Council panel concluded that the regime stole $3 billion in crypto between 2017 and 2023. Given that the Kim Jong Un government is the target of strict international sanctions, the regime has turned to stealing crypto to fund its nuclear weapons program.

More TechCrunch

The North Korean hackers’ attack started by tricking a victim into visiting a web domain under the hackers’ control.

North Korean hackers exploited Chrome zero-day to steal crypto
Image Credits: Contributor / Getty Images

Some stories emerge and die in a matter of days. Others require us to stay tuned for more, and this week brought us several of these.

Fundraising is a lot easier when you have traction

Google is gearing up for the upcoming U.S. presidential election by rolling out safeguards for more of its generative AI products. Although the company already previously announced that it would…

Google rolls out safeguards for more of its AI products ahead of the US presidential election

Across the world, regulators have ramped up their efforts to try and increase the safety of kids on the internet. Major social networks are facing scrutiny, and as a countermeasure,…

Hello Wonder is building an AI-powered browser for kids

Jam & Tea Studios is the latest gaming startup implementing generative AI to transform the way players interact with non-playable characters (NPCs) in video games.  Traditionally, video game NPCs are…

Former Riot Games employees leverage generative AI to power NPCs in new video game

Traditionally seen as private financial entities, family offices are key players in the supply of venture capital, using startup investments as a way to diversify their portfolios and engage with…

Elle Family Office and Keebeck Wealth Management are coming to TechCrunch Disrupt 2024

TechCrunch Disrupt 2024 in San Francisco is just two months away, and we’re still looking for enthusiastic and driven volunteers to assist our events team. Don’t miss this opportunity to…

Be a volunteer at TechCrunch Disrupt 2024

Don’t miss out! Today is the last day to apply and scale your Series A to B startup at a significantly reduced exhibit cost with the ScaleUp Startup Exhibitor Package.…

Last Day: Exhibit your startup with big savings at TechCrunch Disrupt 2024

Indian tech and media startup VerSe, which operates popular news aggregator Dailyhunt, is worth about 42% below its last private valuation, according to estimates by its investor 360 One.  The…

Dailyhunt parent VerSe’s valuation gets slashed 42% to $2.9B: investor note

After seeing double-digit growth in South Korea, Uber Technologies has announced a strategic plan to double down in the country — directly challenging market leader Kakao Mobility, the ride-hailing unit…

Uber drives deeper into South Korea to take on Kakao Mobility

TikTok is introducing a new “Manage Topics” feature that will give you more control over what you see on your For You feed, the company announced on Friday. The new…

TikTok’s new ‘Manage Topics’ tool gives you more control over your For You feed; here’s how to use it

Given everything you’ve already heard about AI, you may not be surprised to learn that Google is among other outfits beginning to use sound signals to predict early signs of…

Google is working on AI that can hear signs of sickness

Nvidia and Apple are reportedly in talks to contribute to OpenAI’s next fundraising round — a round that could value the ChatGPT maker at $100 billion. Per its sources, The…

Apple and Nvidia could be OpenAI’s next big investors

Agrim has raised $17.3 million to expand its B2B agri-inputs platform to more manufacturers and retailers in India.

India’s Agrim snags $17.3M to help farmers get inputs like seeds and pesticides more easily

Intuitive Machines, the venture-backed startup that went public last year, will send a moon lander to the lunar south pole in 2027 as part of a $116.9 million contract awarded…

Intuitive Machines wins $116.9M contract for a moon mission in 2027

Many tech companies are expanding their reach into the web3 market, integrating blockchain and web3 technologies into their products and services. In the latest development, South Korean internet giant Naver…

South Korean tech giant Naver launches crypto wallet in partnership with Chiliz

Atlassian plans to integrate Rewatch into its recently launched Rovo AI platform so that transcripts become searchable within the overall business context.

Atlassian acquires Rewatch as it gets into AI meeting bots

Sub.club thinks premium feeds could also serve other use cases, like supporting helpful bots or generating funds to help maintain a community’s Mastodon server, for instance.

Sub.club aims to fund the fediverse via premium feeds

Gmail users on Android devices can now chat directly with Google’s AI assistant, Gemini, about their emails in the Gmail app. Google rolled out the new feature, Gmail Q&A, on…

Gmail users on Android can now chat with Gemini about their emails

It seems that the Ministry of Truth has been busy at Tesla. Some sharp-eyed folks, including reporters at Electrek, noticed that Tesla has deleted all of its blog posts prior…

Tesla keeps putting its digital history in the memory hole

When streaming to connected devices via Spotify Connect on iOS, users were previously able to use the physical buttons on their iPhone to adjust the volume. But this will no…

Spotify points finger at Apple over an unwelcome change to volume control technology

Magic, an AI startup creating models to generate code and automate a range of software development tasks, has raised a large tranche of cash from investors, including ex-Google CEO Eric…

Generative AI coding startup Magic lands $320M investment from Eric Schmidt, Atlassian and others

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of transportation. Sign up here for free — just click TechCrunch Mobility! The EV…

Uber cozies up to more AV companies, Canoo loses another founder and Waymo sees potential in teen riders

Ahead of the NFL and college football (NCAAF) seasons, Apple announced updates for its sports-focused app, including Live Activities for all leagues, a new “dynamic drive tracker” that visualizes where…

Apple Sports gets updated ahead of football season with Live Activities, play-by-play and more

One of the people who successfully sued the National Association of Realtors (NAR) to change real estate commissions has co-founded a new real estate startup. It all began in 2017…

After winning a landmark case against real estate agents, this startup aims to replace them with a flat fee

X, the Elon Musk-owned platform formerly known as Twitter, is marking some links to news organization NPR’s website as “unsafe” when users click through to read the latest story about…

X caught blocking links to NPR, claiming the news site may be ‘unsafe’

Apple is likely to unveil its iPhone 16 series of phones and maybe even some Apple Watches at its Glowtime event on September 9.

Apple event 2024: How to watch the iPhone 16 launch

Codeium, a startup developing an AI-powered tool to rival GitHub Copilot, has raised $150 million at a $1.25 billion valuation.

GitHub Copilot competitor Codeium raises $150M at a $1.25B valuation

Seattle’s Airport is still largely offline, causing chaos among travelers and acting as a standing warning against taking cybersecurity lightly.

Flying through Seattle’s hacked airport

Earlier this month, Google released a new feature with the Pixel 9 series phone to let users add the photographer to a group photo by swapping someone out and taking…

Two Oxford PhDs are building an app to let you remix photos into memes