Chrome 0-day exploit CVE-2019-13720 used in Operation WizardOpium
2019-11-01 • Kaspersky •
https://securelist.com/chrome-0-day-exploit-cve-2019-13720-used-in-operation-wizardopium/94866/
Kaspersky reported Operation WizardOpium, a Chrome zero-day exploitation campaign using CVE-2019-13720 before Google patched it in Chrome 78.0.3904.87. The attack profiled browsers, pulled exploit chunks from attacker infrastructure, used an image-delivered key and RC4 material to decrypt the exploit code, then downloaded an encrypted final payload that was decrypted, dropped as updata.exe, and persisted through Windows Task Scheduler. Kaspersky explicitly avoided firm attribution, noting only very weak Lazarus code similarities that could be false flags and that the targeted-site profile more closely resembled earlier DarkHotel-style activity. For DPRK tracking, the report is relevant mainly because of the possible but uncertain Lazarus overlap and the operation’s advanced browser-exploit tradecraft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | f614909fbd57ece81d00b01958338ec2 | 2019-11-01 | 2019-11-01 |
| HASH | cafe8f704095b1f5e0a885f75b1b41a… | 2019-11-01 | 2019-11-01 |
| HASH | 27e941683d09a7405a9e806cc7d156c9 | 2019-11-01 | 2019-11-01 |
| HASH | 8fb2558765cf648305493e1dfea7a2b… | 2019-11-01 | 2019-11-01 |
| HASH | 8f3cd9299b2f241daf1f5057ba0b9054 | 2019-11-01 | 2019-11-01 |
| HASH | 35373d07c2e408838812ff210aa28d9… | 2019-11-01 | 2019-11-01 |
| [email protected] | 2019-11-01 | 2019-11-01 | |
| URL | http://code.jquery.cdn.behindco… | 2019-11-01 | 2019-11-01 |
| DOMAIN | behindcorona.com | 2019-11-01 | 2019-11-01 |
| DOMAIN | code.jquery.cdn.behindcorona.com | 2019-11-01 | 2019-11-01 |