logo

Suspected North Korean hackers targeted crypto industry with Chromium zero-day

ID: ff148582-9fae-5684-bbf2-e56e32eb5f2b

STIX ID: report--ff148582-9fae-5684-bbf2-e56e32eb5f2b

Feed Name: The Record from Recorded Future News

Threat Score
90/100

Date Published: 2024-08-30

Date Updated: 2026-05-01

...
...

Microsoft reported that a North Korean-linked APT called 'Citrine Sleet' exploited a Chromium zero-day (CVE-2024-7971) in the wild to target cryptocurrency firms, using fake websites and malicious wallet/trading apps to deliver AppleJeus and FudModule malware for asset theft; Google issued a patch and CISA listed the CVE as known exploited.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.