Lazarus APT steals cryptocurrency and user data via a decoy MOBA game
2024-10-23 • Kaspersky •
https://securelist.com/lazarus-apt-steals-crypto-with-a-tank-game/114282/
Kaspersky linked a Manuscrypt infection on a Russian user's PC to Lazarus activity delivered through detankzone[.]com, a fake DeFi NFT MOBA tank-game site. Visiting the site triggered hidden JavaScript that exploited a Google Chrome zero-day to gain remote code execution before the game download served as a distraction. The exploit chain included CVE-2024-4947 in Chrome's V8 Maglev compiler and a second step to bypass the V8 sandbox, giving attackers control of the victim system. Google patched the issue after disclosure and blocked campaign-related sites, while Microsoft separately tracked related North Korean activity under Moonstone Sleet but did not initially identify the browser zero-day component.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | detankzone.com | 2024-10-23 | 2025-08-25 |
| DOMAIN | api.detankzone.com | 2024-10-23 | 2025-08-25 |
| DOMAIN | ccwaterfall.com | 2024-05-28 | 2024-10-24 |
| HASH | 7f28ad5ee9966410b15ca85b7facb70… | 2024-10-23 | 2024-10-23 |
| HASH | b2dc7aec2c6d2ffa28219ac288e4750c | 2024-10-23 | 2024-10-23 |
| HASH | e5da4ab6366c5690dfd1bb386c7fe0c… | 2024-10-23 | 2024-10-23 |
| HASH | 8312e556c4eec999204368d69ba91bf4 | 2024-10-23 | 2024-10-23 |
| HASH | 59a37d7d2bf4cffe31407edd286a811… | 2024-10-23 | 2024-10-23 |
| HASH | 7353ab9670133468081305bd442f769… | 2024-10-23 | 2024-10-23 |