North Korean threat actor Citrine Sleet exploiting Chromium zero-day
ID: 80b06156-9e3d-57f0-9e7a-7a8b60011448
STIX ID: report--80b06156-9e3d-57f0-9e7a-7a8b60011448
Feed Name: Microsoft Security
Date Published: 2024-08-30
Date Updated: 2026-04-28
Author: Microsoft Threat Intelligence and Microsoft Security Response Center (MSRC)
Microsoft reports that the North Korean threat actor Citrine Sleet actively exploited a Chromium V8 zero-day (CVE-2024-7971) to gain renderer RCE, chained a Windows kernel sandbox escape (CVE-2024-38106), and deployed the sophisticated FudModule rootkit to target the cryptocurrency sector; the blog provides attribution context, IOCs (e.g., voyagorclub.space, weinsteinfrog.com), mitigation guidance, detection rules, and hunting queries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
