North Korean hackers exploit Chrome’s defect to steal crypto

Jeong Mi-ha 2024. 9. 1. 10:01
글자크기 설정 파란원을 좌우로 움직이시면 글자크기가 변경 됩니다.

이 글자크기로 변경됩니다.

(예시) 가장 빠른 뉴스가 있고 다양한 정보, 쌍방향 소통이 숨쉬는 다음뉴스를 만나보세요. 다음뉴스는 국내외 주요이슈와 실시간 속보, 문화생활 및 다양한 분야의 뉴스를 입체적으로 전달하고 있습니다.

A North Korean hacking group, known as “Citrine Sleet,” has been exploiting a newly discovered vulnerability in Google’s Chrome browser to conduct sophisticated cryptocurrency thefts, targeting both institutions and individuals. The photo is unrelated to the articel. /Yonhap News

A North Korean hacking group, known as “Citrine Sleet,” exploited a newly discovered vulnerability in Google’s Chrome browser to steal cryptocurrency from institutions and individuals, according to a recent disclosure.

On Aug. 30, Microsoft (MS) announced that a North Korean hacking group exploited a vulnerability in Google’s Chrome browser to steal cryptocurrency.

According to MS, Citrine Sleet exploited a previously undiscovered bug in Chrome to hack into institutions and individuals in an effort to steal cryptocurrency. MS discovered this activity on Aug. 19, and Google confirmed and patched the bug two days after the discovery. However, it remains unclear how many people were affected by the attack. MS stated that it has notified those who were targeted.

MS described Citrine Sleet as a group primarily targeting financial institutions, particularly those involved in cryptocurrency, with the intent of financial gain. The group has carried out extensive attacks on the cryptocurrency industry and individuals connected to it, often by creating fake websites that mimic legitimate cryptocurrency trading platforms. They have also distributed fake job applications and tricked users into downloading cryptocurrency wallets or trading apps disguised as legitimate software.

Additionally, Citrine Sleet has deployed a custom-developed Trojan malware called “AppleJeus” to infect PCs and collect the information needed to steal cryptocurrency assets from their victims.

Copyright © 조선일보. 무단전재 및 재배포 금지.