市值: $2.2043T 0.58%
體積(24小時): $56.8553B 3.76%
  • 市值: $2.2043T 0.58%
  • 體積(24小時): $56.8553B 3.76%
  • 恐懼與貪婪指數:
  • 市值: $2.2043T 0.58%
加密
主題
加密植物
資訊
加密術
影片
頭號新聞
加密
主題
加密植物
資訊
加密術
影片
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

加密貨幣新聞文章

Lazarus 集團利用假區塊鏈遊戲利用 Google Chrome 的零日漏洞

2024/10/24 05:34

北韓拉撒路駭客組織利用基於區塊鏈的虛假遊戲利用谷歌 Chrome 瀏覽器中的零日漏洞並安裝間諜軟體

Lazarus 集團利用假區塊鏈遊戲利用 Google Chrome 的零日漏洞

North Korean Lazarus Group hackers have exploited a zero-day vulnerability in Google Chrome to install spyware that steals wallet credentials, using a fake blockchain-based game to carry out the attack.

北韓 Lazarus Group 駭客利用 Google Chrome 中的零日漏洞安裝間諜軟體,竊取錢包憑證,並使用虛假的基於區塊鏈的遊戲來實施攻擊。

The Lazarus Group’s activities were detected by Kaspersky Labs analysts in May, who reported the exploit to Google. The vulnerability has since been fixed by Google.

卡巴斯基實驗室分析師在 5 月發現了 Lazarus Group 的活動,並向 Google 報告了該漏洞。該漏洞已被谷歌修復。

Playing at a high risk

玩遊戲的風險很高

The hackers’ game, which was fully playable, was promoted on LinkedIn and X. It was called DeTankZone or DeTankWar and featured tanks represented by non-fungible tokens (NFTs) that competed in a global tournament.

這款完全可玩的黑客遊戲在 LinkedIn 和 X 上進行了推廣。

Interestingly, users could get infected from the game’s website even without downloading the game itself. The hackers reportedly modeled the game on the existing DeFiTankLand.

有趣的是,即使用戶沒有下載遊戲本身,也可能從遊戲網站感染。據報道,駭客以現有的 DeFiTankLand 為模型設計了這款遊戲。

According to the report, the hackers deployed Manuscrypt malware, followed by a previously unseen “type confusion bug in the V8 JavaScript engine.” This marked the seventh zero-day vulnerability found in Chrome in 2024 up to mid-May.

根據該報告,駭客部署了 Manuscrypt 惡意軟體,隨後出現了以前未見過的「V8 JavaScript 引擎中的類型混淆錯誤」。這是 2024 年截至 5 月中旬 Chrome 中發現的第七個零日漏洞。

“The fake game was noticed by Microsoft Security back in February. However, by the time Kaspersky was able to look into it, the threat actor had already removed the exploit from the website,” Boris Larin, principal security expert at Kaspersky, told Securelist.

「微軟安全部門早在二月就注意到了這款假遊戲。然而,當卡巴斯基能夠調查它時,威脅行為者已經從網站上刪除了該漏洞,」卡巴斯基首席安全專家 Boris Larin 告訴 Securelist。

Despite this, the lab went ahead and informed Google about the exploit, and Chrome fixed the vulnerability before the hackers could reintroduce it.

儘管如此,該實驗室還是繼續向谷歌通報了該漏洞,Chrome 在駭客重新引入該漏洞之前修復了該漏洞。

Screenshot from Lazarus Group’s fake game, as shared by SecureList

SecureList 分享的 Lazarus Group 假遊戲的螢幕截圖

Related: FBI highlights 6 Bitcoin wallets linked to North Korea, urging crypto exchanges to be vigilant

相關:FBI 強調 6 個與北韓有關的比特幣錢包,敦促加密貨幣交易所保持警惕

North Korea has a thing for crypto

北韓熱衷於加密貨幣

Zero-day vulnerabilities are those that a vendor is made aware of for the first time, without any patch being ready for it. In this case, it took Google 12 days to patch the vulnerability in question.

零日漏洞是供應商在沒有準備任何修補程式的情況下首次發現的漏洞。在這種情況下,Google花了 12 天的時間來修復相關漏洞。

Earlier this year, another zero-day vulnerability in Chrome was exploited by a separate North Korean hacker group to target crypto holders.

今年早些時候,Chrome 中的另一個零日漏洞被一個獨立的北韓駭客組織利用,以加密貨幣持有者為目標。

As reported by Microsoft Threat Intelligence, Lazarus Group is known to have a strong preference for cryptocurrency. According to crypto crime watcher ZachXBT, the group laundered over $200 million in crypto from 25 hacks between 2020 and 2023.

根據 Microsoft Threat Intelligence 報導,眾所周知,Lazarus Group 對加密貨幣有著強烈的偏好。據加密貨幣犯罪觀察者 ZachXBT 稱,該組織在 2020 年至 2023 年間透過 25 次駭客攻擊洗掉了超過 2 億美元的加密貨幣。

The United States Treasury Department has also accused Lazarus Group of being behind the 2022 attack on Ronin Bridge, which resulted in the theft of crypto valued at over $600 million.

美國財政部還指控 Lazarus Group 是 2022 年 Ronin Bridge 襲擊事件的幕後黑手,該事件導致價值超過 6 億美元的加密貨幣被盜。

Over the seven-year period from 2017 to 2023, North Korean hackers stole a total of more than $3 billion in crypto, according to cybersecurity firm Recorded Future.

根據網路安全公司 Recorded Future 的數據,從 2017 年到 2023 年的七年時間裡,北韓駭客總共竊取了超過 30 億美元的加密貨幣。

Magazine: Lazarus Group’s favorite exploit revealed — An analysis of crypto hacks by the notorious group

雜誌:Lazarus Group 最喜歡的漏洞被揭露——該臭名昭著的組織對加密貨幣黑客的分析

原始來源:cointelegraph

免責聲明:info@kdj.com

所提供的資訊並非交易建議。 kDJ.com對任何基於本文提供的資訊進行的投資不承擔任何責任。加密貨幣波動性較大,建議您充分研究後謹慎投資!

如果您認為本網站使用的內容侵犯了您的版權,請立即聯絡我們(info@kdj.com),我們將及時刪除。

2026年08月12日 其他文章發表於