Lazarus Hackers Launch Fake NFT Game to Hack Chrome

3 Min Read Tags:

  • North Korean hackers from Lazarus Group have devised a new cyber scheme targeting cryptocurrency users.
  • The group created a fake NFT game to exploit a vulnerability in the Google Chrome browser.
  • The malware involved was designed to gather sensitive information from unsuspecting users.
  • Google has since patched the zero-day vulnerability, eliminating the immediate threat.

Lazarus Group Hackers Create Fake NFT Game to Exploit Google Chrome

In a significant cybersecurity revelation, the infamous North Korean hacking group, Lazarus Group, has once again made headlines. The group is known for its sophisticated cyber schemes, and this time, they have created a fake NFT game to exploit vulnerabilities in the Google Chrome browser. According to a recent report by BleepingComputer, the malware targeted cryptocurrency users by masquerading as a legitimate online game.

The Deceptive Game: DeTankZone

In February 2024, security experts discovered an online campaign promoting a multiplayer NFT game called DeTankZone. The hackers behind this campaign used aggressive marketing techniques, leveraging social media and email communications to lure users into downloading the game. However, DeTankZone was merely a facade; it was based on stolen source code from a genuine product called DeFiTankLand. Upon downloading the 400 MB file, users encountered a non-functional game after attempting to register and log in. This failure was due to the absence of any real infrastructure to support the game.

The Threat: Manuscrypt Backdoor

Instead of entertainment, users inadvertently downloaded a malicious backdoor named Manuscrypt. This software executed a zero-day attack on Google Chrome, exploiting the vulnerability identified as CVE-2024-4947. Through this exploit, hackers gained unauthorized access to cookies, authentication tokens, saved passwords, and browsing histories. The malware served as an intelligence-gathering tool, with a particular focus on identifying individuals possessing cryptocurrency assets.

Security Implications and Google’s Response

The Lazarus Group used their development to scout and collect data on potential targets. The information gathered was transmitted to the hackers’ server, and further invasive actions were taken, including modifications to the victim’s BIOS settings. Although the exact number of affected computers remains unknown, experts emphasize that Google addressed the vulnerability on May 25, 2024. Thus, the threat posed by CVE-2024-4947 has been neutralized.

Broader Impact on the Crypto Market

This incident underscores the persistent risks faced by cryptocurrency users, highlighting the need for vigilance and robust security measures. As hackers continuously evolve their tactics, the cryptocurrency community must remain proactive in safeguarding digital assets. This situation serves as a stark reminder of the importance of timely software updates and the implementation of strong cybersecurity practices to defend against emerging threats. The swift action by Google to patch the vulnerability demonstrates the critical role of tech companies in protecting users against sophisticated cyber attacks.

TAGGED:
Anthropic Models 3 US Economic Scenarios Through 2030

Anthropic published a model outlining three scenarios for the U.S. economy through 2030, with its extreme scenario suggesting annual GDP growth could reach 15% alongside historically high unemployment.

7 Min Read
Robinhood CEO Says Companies Cannot Control Tokenization of Their Shares

In September 2026, Robinhood CEO Vlad Tenev said companies cannot prevent third-party products linked to their shares, defending 1:1 share-backed Stock Tokens after AMC CEO Adam Aron challenged their legality.

5 Min Read
Germany Will Change Crypto-Asset Tax Rules in 2027, Media Reports

Germany’s draft crypto tax reforms would from Jan. 1, 2027, tax profits on covered assets acquired after Dec. 31, 2026, regardless of holding period, while platforms would begin withholding tax…

5 Min Read
Vitalik Buterin Says Recursive STARKs Could Cut Ethereum Private, Post-Quantum Transaction Costs

On Sept. 9, Ethereum co-founder Vitalik Buterin explained EIP-8288, a proposal to aggregate STARK proofs and cryptographic signatures at the mempool level, potentially reducing costs without changing the EVM.

6 Min Read
Bybit Launches AI Assistant for Trading, Account Management

Bybit announced the launch of Bybit AI, a voice assistant that lets eligible users access trading, account management and customer support through one app chat interface after activating an isolated…

4 Min Read