logo

Lazarus hackers used fake DeFi game to exploit Google Chrome zero-day

ID: 0ca398cd-6fc1-585e-a5b2-fbe24ec6748f

STIX ID: report--0ca398cd-6fc1-585e-a5b2-fbe24ec6748f

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-10-23

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Kaspersky uncovered a Lazarus campaign (beginning Feb 2024) using a fake NFT/DeFi tank game to host an exploit chain that abused a Chrome V8 type confusion (CVE-2024-4947) and a separate V8 sandbox escape to execute shellcode and deploy a Manuscrypt backdoor for reconnaissance and likely cryptocurrency theft; Google released a patch for the Chrome zero-day on May 25, 2024.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.