시가총액: $2.1753T 0.52%
거래량(24시간): $38.8228B -29.97%
  • 시가총액: $2.1753T 0.52%
  • 거래량(24시간): $38.8228B -29.97%
  • 공포와 탐욕 지수:
  • 시가총액: $2.1753T 0.52%
암호화
주제
암호화
소식
cryptostopics
비디오
최고의 뉴스
암호화
주제
암호화
소식
cryptostopics
비디오
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

암호화폐 뉴스 기사

Lazarus Group은 가짜 블록체인 게임을 사용해 Google Chrome의 제로데이 취약점을 악용했습니다.

2024/10/24 05:34

북한 라자루스 해커그룹이 가짜 블록체인 기반 게임을 사용해 구글 크롬 브라우저의 제로데이 취약점을 악용해 스파이웨어를 설치했다.

Lazarus Group은 가짜 블록체인 게임을 사용해 Google Chrome의 제로데이 취약점을 악용했습니다.

North Korean Lazarus Group hackers have exploited a zero-day vulnerability in Google Chrome to install spyware that steals wallet credentials, using a fake blockchain-based game to carry out the attack.

북한 라자루스 그룹 해커들이 구글 크롬의 제로데이 취약점을 이용해 지갑 자격 증명을 훔치는 스파이웨어를 설치하고 가짜 블록체인 기반 게임을 이용해 공격을 감행했다.

The Lazarus Group’s activities were detected by Kaspersky Labs analysts in May, who reported the exploit to Google. The vulnerability has since been fixed by Google.

Lazarus Group의 활동은 지난 5월 Kaspersky Labs 분석가에 의해 감지되었으며 Google에 해당 익스플로잇을 보고했습니다. 이후 Google은 취약점을 수정했습니다.

Playing at a high risk

높은 위험을 감수하고 플레이

The hackers’ game, which was fully playable, was promoted on LinkedIn and X. It was called DeTankZone or DeTankWar and featured tanks represented by non-fungible tokens (NFTs) that competed in a global tournament.

완전히 플레이 가능한 해커 게임은 LinkedIn과 X에서 홍보되었습니다. DeTankZone 또는 DeTankWar라고 불리며 NFT(Non-Fungible Token)로 대표되는 탱크가 글로벌 토너먼트에 참가했습니다.

Interestingly, users could get infected from the game’s website even without downloading the game itself. The hackers reportedly modeled the game on the existing DeFiTankLand.

흥미롭게도 사용자는 게임 자체를 다운로드하지 않고도 게임 웹사이트에서 감염될 수 있습니다. 해커들은 기존 DeFiTankLand를 기반으로 게임을 모델링한 것으로 알려졌습니다.

According to the report, the hackers deployed Manuscrypt malware, followed by a previously unseen “type confusion bug in the V8 JavaScript engine.” This marked the seventh zero-day vulnerability found in Chrome in 2024 up to mid-May.

보고서에 따르면 해커는 Manuscrypt 악성 코드를 배포한 후 이전에는 볼 수 없었던 "V8 JavaScript 엔진의 유형 혼동 버그"를 배포했습니다. 이는 2024년 5월 중순까지 Chrome에서 발견된 7번째 제로데이 취약점입니다.

“The fake game was noticed by Microsoft Security back in February. However, by the time Kaspersky was able to look into it, the threat actor had already removed the exploit from the website,” Boris Larin, principal security expert at Kaspersky, told Securelist.

“가짜 게임은 지난 2월 Microsoft Security에 의해 발견되었습니다. 그러나 Kaspersky가 이를 조사할 수 있었을 때 위협 행위자는 이미 웹사이트에서 익스플로잇을 제거한 상태였습니다.”라고 Kaspersky의 수석 보안 전문가인 Boris Larin은 Securelist에 말했습니다.

Despite this, the lab went ahead and informed Google about the exploit, and Chrome fixed the vulnerability before the hackers could reintroduce it.

그럼에도 불구하고 연구실에서는 해당 익스플로잇에 대해 Google에 알렸고 Chrome은 해커가 취약점을 다시 도입하기 전에 취약점을 수정했습니다.

Screenshot from Lazarus Group’s fake game, as shared by SecureList

SecureList에서 공유한 Lazarus Group의 가짜 게임 스크린샷

Related: FBI highlights 6 Bitcoin wallets linked to North Korea, urging crypto exchanges to be vigilant

관련: FBI, 북한과 연결된 비트코인 ​​지갑 6개 발견, 암호화폐 거래소에 경계 촉구

North Korea has a thing for crypto

북한은 암호화폐에 관심이 있다

Zero-day vulnerabilities are those that a vendor is made aware of for the first time, without any patch being ready for it. In this case, it took Google 12 days to patch the vulnerability in question.

제로데이 취약점은 패치가 준비되지 않은 상태에서 공급업체가 처음으로 알게 되는 취약점입니다. 이 경우 Google이 문제의 취약점을 패치하는 데 12일이 걸렸습니다.

Earlier this year, another zero-day vulnerability in Chrome was exploited by a separate North Korean hacker group to target crypto holders.

올해 초 별도의 북한 해커 그룹이 암호화폐 보유자를 표적으로 삼기 위해 크롬의 또 다른 제로데이 취약점을 악용했습니다.

As reported by Microsoft Threat Intelligence, Lazarus Group is known to have a strong preference for cryptocurrency. According to crypto crime watcher ZachXBT, the group laundered over $200 million in crypto from 25 hacks between 2020 and 2023.

Microsoft Threat Intelligence에서 보고한 바와 같이 Lazarus Group은 암호화폐를 매우 선호하는 것으로 알려져 있습니다. 암호화폐 범죄 감시자 ZachXBT에 따르면 이 그룹은 2020년부터 2023년까지 25건의 해킹을 통해 2억 달러 이상의 암호화폐를 세탁했습니다.

The United States Treasury Department has also accused Lazarus Group of being behind the 2022 attack on Ronin Bridge, which resulted in the theft of crypto valued at over $600 million.

미국 재무부는 또한 2022년 로닌 브리지(Ronin Bridge) 공격으로 인해 6억 달러 이상의 가치가 있는 암호화폐를 도난당한 사건의 배후에 라자루스 그룹(Lazarus Group)이 있다고 비난했습니다.

Over the seven-year period from 2017 to 2023, North Korean hackers stole a total of more than $3 billion in crypto, according to cybersecurity firm Recorded Future.

사이버 보안 회사인 Recorded Future에 따르면, 2017년부터 2023년까지 7년 동안 북한 해커들은 총 30억 달러 이상의 암호화폐를 훔쳤습니다.

Magazine: Lazarus Group’s favorite exploit revealed — An analysis of crypto hacks by the notorious group

매거진: Lazarus Group이 가장 선호하는 익스플로잇 공개 — 악명 높은 그룹의 암호화폐 해킹 분석

원본 소스:cointelegraph

부인 성명:info@kdj.com

제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!

본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

2026年08月02日 에 게재된 다른 기사