Lazarus APT steals cryptocurrency and user data via a decoy MOBA game

2024-10-23 Kaspersky

https://securelist.com/lazarus-apt-steals-crypto-with-a-tank-game/114282/

Thumbnail for Lazarus APT steals cryptocurrency and user data via a decoy MOBA game

Kaspersky linked a Manuscrypt infection on a Russian user's PC to Lazarus activity delivered through detankzone[.]com, a fake DeFi NFT MOBA tank-game site. Visiting the site triggered hidden JavaScript that exploited a Google Chrome zero-day to gain remote code execution before the game download served as a distraction. The exploit chain included CVE-2024-4947 in Chrome's V8 Maglev compiler and a second step to bypass the V8 sandbox, giving attackers control of the victim system. Google patched the issue after disclosure and blocked campaign-related sites, while Microsoft separately tracked related North Korean activity under Moonstone Sleet but did not initially identify the browser zero-day component.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN detankzone.com 2024-10-23 2025-08-25
DOMAIN api.detankzone.com 2024-10-23 2025-08-25
DOMAIN ccwaterfall.com 2024-05-28 2024-10-24
HASH 7f28ad5ee9966410b15ca85b7facb70… 2024-10-23 2024-10-23
HASH b2dc7aec2c6d2ffa28219ac288e4750c 2024-10-23 2024-10-23
HASH e5da4ab6366c5690dfd1bb386c7fe0c… 2024-10-23 2024-10-23
HASH 8312e556c4eec999204368d69ba91bf4 2024-10-23 2024-10-23
HASH 59a37d7d2bf4cffe31407edd286a811… 2024-10-23 2024-10-23
HASH 7353ab9670133468081305bd442f769… 2024-10-23 2024-10-23

Related Actors

Related Reports

« Back