時価総額: $2.1745T 0.53%
ボリューム(24時間): $38.421B -36.01%
  • 時価総額: $2.1745T 0.53%
  • ボリューム(24時間): $38.421B -36.01%
  • 恐怖と貪欲の指数:
  • 時価総額: $2.1745T 0.53%
暗号
トピック
暗号化
ニュース
暗号造園
動画
トップニュース
暗号
トピック
暗号化
ニュース
暗号造園
動画
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

暗号通貨のニュース記事

Lazarus グループは偽のブロックチェーン ゲームを使用して Google Chrome のゼロデイ脆弱性を悪用しました

2024/10/24 05:34

北朝鮮のハッカー集団「Lazarus Group」が偽のブロックチェーンベースのゲームを利用してGoogleのChromeブラウザのゼロデイ脆弱性を悪用し、スパイウェアをインストールした

Lazarus グループは偽のブロックチェーン ゲームを使用して Google Chrome のゼロデイ脆弱性を悪用しました

North Korean Lazarus Group hackers have exploited a zero-day vulnerability in Google Chrome to install spyware that steals wallet credentials, using a fake blockchain-based game to carry out the attack.

北朝鮮の Lazarus Group ハッカーは、Google Chrome のゼロデイ脆弱性を悪用し、ウォレットの認証情報を盗むスパイウェアをインストールし、偽のブロックチェーンベースのゲームを使用して攻撃を実行しました。

The Lazarus Group’s activities were detected by Kaspersky Labs analysts in May, who reported the exploit to Google. The vulnerability has since been fixed by Google.

Lazarus Group の活動は 5 月に Kaspersky Labs のアナリストによって発見され、Google にエクスプロイトを報告しました。その後、この脆弱性は Google によって修正されました。

Playing at a high risk

ハイリスクでのプレイ

The hackers’ game, which was fully playable, was promoted on LinkedIn and X. It was called DeTankZone or DeTankWar and featured tanks represented by non-fungible tokens (NFTs) that competed in a global tournament.

このハッカーのゲームは完全にプレイ可能で、LinkedIn と X で宣伝されました。このゲームは DeTankZone または DeTankWar と呼ばれ、代替不可能なトークン (NFT) で表される戦車が世界的なトーナメントで競い合いました。

Interestingly, users could get infected from the game’s website even without downloading the game itself. The hackers reportedly modeled the game on the existing DeFiTankLand.

興味深いことに、ユーザーはゲーム自体をダウンロードしなくても、ゲームの Web サイトから感染する可能性があります。伝えられるところによると、ハッカーたちは既存の DeFiTankLand をモデルにしてゲームを作成したとのこと。

According to the report, the hackers deployed Manuscrypt malware, followed by a previously unseen “type confusion bug in the V8 JavaScript engine.” This marked the seventh zero-day vulnerability found in Chrome in 2024 up to mid-May.

報告書によると、ハッカーは Manuscrypt マルウェアを展開し、その後、これまで見たことのない「V8 JavaScript エンジンの型混乱バグ」が発生しました。これは、2024 年に Chrome で 5 月中旬までに発見された 7 件目のゼロデイ脆弱性です。

“The fake game was noticed by Microsoft Security back in February. However, by the time Kaspersky was able to look into it, the threat actor had already removed the exploit from the website,” Boris Larin, principal security expert at Kaspersky, told Securelist.

「偽のゲームは 2 月にマイクロソフト セキュリティによって発見されました。しかし、カスペルスキーが調査できたときには、攻撃者はすでにそのエクスプロイトを Web サイトから削除していました」とカスペルスキーの主任セキュリティ専門家であるボリス・ラリン氏はセキュアリストに語った。

Despite this, the lab went ahead and informed Google about the exploit, and Chrome fixed the vulnerability before the hackers could reintroduce it.

それにもかかわらず、研究所は先にこのエクスプロイトについて Google に通知し、ハッカーが再導入する前に Chrome が脆弱性を修正しました。

Screenshot from Lazarus Group’s fake game, as shared by SecureList

SecureList によって共有された、Lazarus Group の偽ゲームのスクリーンショット

Related: FBI highlights 6 Bitcoin wallets linked to North Korea, urging crypto exchanges to be vigilant

関連:FBIが北朝鮮に関連する6つのビットコインウォレットを強調し、仮想通貨取引所に警戒するよう呼びかけ

North Korea has a thing for crypto

北朝鮮は仮想通貨に興味がある

Zero-day vulnerabilities are those that a vendor is made aware of for the first time, without any patch being ready for it. In this case, it took Google 12 days to patch the vulnerability in question.

ゼロデイ脆弱性とは、パッチが準備されていない状態で、ベンダーが初めて認識する脆弱性です。この場合、Google が問題の脆弱性を修正するのに 12 日かかりました。

Earlier this year, another zero-day vulnerability in Chrome was exploited by a separate North Korean hacker group to target crypto holders.

今年初め、Chrome の別のゼロデイ脆弱性が別の北朝鮮ハッカー グループによって悪用され、仮想通貨保有者を標的にしました。

As reported by Microsoft Threat Intelligence, Lazarus Group is known to have a strong preference for cryptocurrency. According to crypto crime watcher ZachXBT, the group laundered over $200 million in crypto from 25 hacks between 2020 and 2023.

Microsoft Threat Intelligence の報告によると、Lazarus Group は暗号通貨を非常に好むことが知られています。暗号通貨犯罪監視者のZachXBTによると、このグループは2020年から2023年の間に25回のハッキングで2億ドル以上の暗号通貨を洗浄したという。

The United States Treasury Department has also accused Lazarus Group of being behind the 2022 attack on Ronin Bridge, which resulted in the theft of crypto valued at over $600 million.

米国財務省はまた、6億ドル以上相当の暗号通貨の盗難をもたらした2022年のローニンブリッジ攻撃の背後にラザルス・グループが関与していると非難した。

Over the seven-year period from 2017 to 2023, North Korean hackers stole a total of more than $3 billion in crypto, according to cybersecurity firm Recorded Future.

サイバーセキュリティ会社レコーデッド・フューチャーによると、2017年から2023年までの7年間に、北朝鮮のハッカーらは総額30億ドル以上の仮想通貨を盗んだ。

Magazine: Lazarus Group’s favorite exploit revealed — An analysis of crypto hacks by the notorious group

マガジン: Lazarus Group のお気に入りのエクスプロイトが明らかに — 悪名高いグループによる暗号ハッキングの分析

オリジナルソース:cointelegraph

免責事項:info@kdj.com

提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。

このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

2026年08月03日 に掲載されたその他の記事