logo

North Korean threat actor Citrine Sleet exploiting Chromium zero-day

ID: 80b06156-9e3d-57f0-9e7a-7a8b60011448

STIX ID: report--80b06156-9e3d-57f0-9e7a-7a8b60011448

Feed Name: Microsoft Security

Threat Score
90/100

Date Published: 2024-08-30

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence and Microsoft Security Response Center (MSRC)

...
...

Microsoft reports that the North Korean threat actor Citrine Sleet actively exploited a Chromium V8 zero-day (CVE-2024-7971) to gain renderer RCE, chained a Windows kernel sandbox escape (CVE-2024-38106), and deployed the sophisticated FudModule rootkit to target the cryptocurrency sector; the blog provides attribution context, IOCs (e.g., voyagorclub.space, weinsteinfrog.com), mitigation guidance, detection rules, and hunting queries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.