North Korean hackers exploit Chrome zero-day to deploy rootkit
ID: 09f5c510-9714-5766-b0d6-469854c554f5
STIX ID: report--09f5c510-9714-5766-b0d6-469854c554f5
Feed Name: Bleeping Computer
Threat Score
Microsoft attributes active exploitation of a Chrome zero-day (CVE-2024-7971) to the North Korean-linked group Citrine Sleet, who redirected victims to attacker-controlled sites to achieve remote code execution, chained a Windows kernel exploit (CVE-2024-38106) to gain SYSTEM privileges, and loaded the FudModule rootkit for kernel tampering and DKOM; the actor targets the cryptocurrency sector and has used supply-chain and trojanized software techniques in prior campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
