logo

North Korean APT Exploits Novel Chromium, Windows Bugs to Steal Crypto

ID: e245fa4d-7aaf-55fd-b6bf-596536bc5097

STIX ID: report--e245fa4d-7aaf-55fd-b6bf-596536bc5097

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2024-09-03

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Microsoft and reporters attribute a sophisticated North Korean APT (Citrine Sleet / Lazarus subset) campaign against the cryptocurrency industry that chained an actively exploited Chromium zero-day (CVE-2024-7971) to a Windows kernel privilege escalation (CVE-2024-38106), deployed the FudModule kernel rootkit to evade defenses, and installed the AppleJeus trojan to steal crypto assets; victims and full impact remain undisclosed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.