Friday, March 25, 2022

 

TECH


Google closes critical Chrome vulnerability exploited by North Korean communist regime hackers

Google announced the discovery and closure of a vulnerability in Chrome that allowed remote code execution in the browser. This vulnerability is believed to have been exploited by North Korean hackers.

According to the UK edition of The Register, quoting Google employee Adam Weidemann, the Chrome vulnerability was identified on February 10th and has been exploited since at least January 4th – a bug in the program made it possible to compromise the victim's browser, seize computer control and perform surveillance. The “target audience” of North Korean intelligence services were employees of American companies in the media, high technology, cryptocurrency and fintech areas, but it is possible that the attackers were also active in other countries and industries.

Exploitation of the vulnerability was carried out by Pyongyang controlled groups Operation Dream Job and Operation AppleJeus – they used the same exploit code but acted according to different scenarios. The Operation Dream Job hackers targeted media workers, domain registrars, ISPs and software vendors. The attackers disguised themselves as human resources experts by sending fake emails about job openings at Google, Oracle and Disney, disguising the messages as real letters from recruiting agencies. Users navigated to websites with hidden iframes that exploited the vulnerability to execute arbitrary code. The Operation AppleJeus group specializes in people involved in cryptocurrencies or employed in the fintech sector – they have also been lured into phishing sites with hidden iframe elements.

Using the JavaScript engine, a computer identifier was created and when a certain set of conditions were met, the exploit was released. If the remote code execution was successful, an attempt was made through JavaScript to move to a new stage of the attack, in which the malicious code bypassed the browser sandbox and gained privileged access to the machine as a whole.

The hackers masterfully covered their tracks: unique links were sent to all victims, which became inaccessible after the first transition, each step was encrypted with the AES algorithm, and if any of the steps failed, further work was stopped. A Google official clarified that the company was able to trace the entire chain of attacks on Chrome, and there was evidence of attempts to implement a similar scenario with Safari and Firefox, but the traces of these attacks have now been destroyed.

AVnews/mundophone

No comments:

Post a Comment

TECH ENISA: DDoS attacks accounted for more than half of the incidents recorded in Europe last year In total, DDoS attacks represented 51.3...