Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Zero Day - North Korean Threat Actor Exploits Chrome Zero-Day
Zero Day Attacks Latest News News & Analysis Threats and Vulnerabilities

North Korean Threat Actor Exploits Chrome Zero-Day

ISB Staff ReporterBy ISB Staff ReporterSeptember 2, 2024Updated:November 8, 20243 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Zero-Day
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

A North Korean threat actor has been found exploiting a zero-day vulnerability in Chromium, now designated as CVE-2024-7971. The exploit, which enables remote code execution (RCE), is being attributed with high confidence to a North Korean group known as Citrine Sleet. The actor primarily targets the cryptocurrency sector for financial gain.

Microsoft’s ongoing analysis has linked the observed exploitation of CVE-2024-7971 to Citrine Sleet. The threat actor has previously been associated with other North Korean groups, including Diamond Sleet, which shares tools and infrastructure with Citrine Sleet. The FudModule rootkit, which has been deployed in this attack, has also been attributed to Diamond Sleet, indicating a possible overlap between the two threat actors.

Google released a fix for the vulnerability on 21 August and urged users to update their Chromium-based browsers to the latest version.

Vulnerability Details

CVE-2024-7971 is a type confusion vulnerability in the V8 JavaScript and WebAssembly engine, affecting versions of Chromium prior to 128.0.6613.84. The vulnerability enables malefactors to execute remote code in the sandboxed Chromium renderer process. This is the third V8 type confusion vulnerability patched this year, following CVE-2024-4947 and CVE-2024-5274.

Microsoft notified affected customers directly and provided them with guidance to secure their systems against this attack.

Citrine Sleet’s Tactics and Targeting

Citrine Sleet is a North Korean threat actor known for targeting financial institutions and individuals managing cryptocurrency assets. The group uses social engineering tactics to lure targets into downloading weaponized applications or visiting malicious websites. Their primary malware, AppleJeus, has been used to gain control over cryptocurrency assets.

In this latest attack, Citrine Sleet directed targets to a malicious domain, voyagorclub[.]space, where the zero-day exploit for CVE-2024-7971 was served. The attack chain also included the use of CVE-2024-38106, a Windows kernel vulnerability that Microsoft patched earlier in August. Once the sandbox escape exploit was successful, the FudModule rootkit was deployed.

FudModule Rootkit

FudModule is sophisticated rootkit malware that targets Windows-based systems by manipulating kernel security mechanisms. Diamond Sleet has been using the rootkit since 2021 and has evolved over time to evade detection.

Additional research by Avast, uncovered a full attack chain deploying the updated variant of FudModule known as “FudModule 2.0,” which features malicious loaders and a late-stage remote access trojan (RAT). This attack chain showed that a previously unknown malware, Kaolin RAT, was the culprit behind loading the FudModule rootkit to targeted devices.

Mitigation and Recommendations

Microsoft has released security updates to address the vulnerabilities exploited in this attack. Users are urged to update their systems and browsers to the latest versions. Additionally, Microsoft recommends implementing the following security measures:

  1. Keep systems and applications up to date: Apply security patches promptly and ensure that browsers like Chrome and Edge are updated to the latest versions.
  2. Enable network protection: Use Microsoft Defender for Endpoint to block malicious websites and phishing attempts.
  3. Run endpoint detection and response (EDR) in block mode: This helps block malicious artifacts even if they are not detected by antivirus software.
  4. Turn on cloud-delivered protection: This feature in Microsoft Defender Antivirus helps protect against rapidly evolving threats.
  5. Enable real-time protection: Ensure that real-time protection is active to detect and block malicious activity.

As North Korean threat actors continue to target the cryptocurrency sector, organizations must remain vigilant and implement robust security measures to protect their assets.

For more information on this threat and detailed guidance on mitigation, please read Microsoft’s full blog.

ISB Staff Reporter
  • ISB Staff Reporter
    Mass Exploit Lets Attackers Install Plugins Arbitrarily
  • ISB Staff Reporter
    Cyberattacks Soar 47% Globally – Attacks on Education Increase by 73%
  • ISB Staff Reporter
    CISA Warns of Two Known Exploited Vulnerabilities
  • ISB Staff Reporter
    JFrog Becomes an AI System of Record, Debuts JFrog ML

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

ShinyHunters targets Oracle PeopleSoft customers through critical zero-day

June 19, 20263 Mins Read

Microsoft discloses Exchange zero-day with no patch yet available

May 18, 20263 Mins Read

WhatsApp Reveals Zero-Day Exploited in Targeted Apple Attacks

September 3, 20253 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}