logo

North Korean hackers exploit Chrome zero-day to deploy rootkit

ID: 09f5c510-9714-5766-b0d6-469854c554f5

STIX ID: report--09f5c510-9714-5766-b0d6-469854c554f5

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-08-30

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft attributes active exploitation of a Chrome zero-day (CVE-2024-7971) to the North Korean-linked group Citrine Sleet, who redirected victims to attacker-controlled sites to achieve remote code execution, chained a Windows kernel exploit (CVE-2024-38106) to gain SYSTEM privileges, and loaded the FudModule rootkit for kernel tampering and DKOM; the actor targets the cryptocurrency sector and has used supply-chain and trojanized software techniques in prior campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.