• Advertise with us
  • Pricing
  • Submit News
Instagram Twitter Facebook Telegram Youtube Linkedin
EdaFace Newsfeed
EdaFace Newsfeed EdaFace
  • News
    • Price Analysis

    Main News

    • Crypto News
    • Bitcoin and BTC
    • Altcoin News
    • Security & Hacks
    • ICO & Token Sales
    • Interviews & Profiles

    Information

    • Press Release
    • Research Report
    • Regulations, Law & Policy
    • Community/Guest Post
    • Events & Conferences
    • Tutorials & Guides

    Market

    • Technical Analysis
    • Price Analysis
    • Cryptocurrency Price Prediction
    • DeFi (Decentralized Finance)
    • Mining & Staking

    Other Categories

    • NFTs & Digital Art
    • Opinion & Editorials
    • Tech Innovations
  • Cryptocurrencies
    • Coin Ranking
    • Trending
    • EDA Token
  • Exchanges
    • Spot
    • Derivatives
    • DEX
    • EDA Plantation
  • Verification Centre
    • Rug Pull Check
    • Blockchain Ecosystem
    • EDA Token
  • MarketPlaces
    • NFT Marketplace
    • Digital Literature
    • Digital Mall
    • P2P Market
    • Metaverse
  • EDA Academy
More
  • News
    • Price Analysis
  • Cryptocurrencies
    • Coin Ranking
    • Trending
    • EDA Token
  • Exchanges
    • Spot
    • Derivatives
    • DEX
    • EDA Plantation
  • Verification Centre
    • Rug Pull Check
    • Blockchain Ecosystem
    • EDA Token
  • MarketPlaces
    • NFT Marketplace
    • Digital Literature
    • Digital Mall
    • P2P Market
    • Metaverse
  • EDA Academy
Reading: Chrome Warnings Were Not in Vain, Crypto Investors Are Victims
Share
Sign In
EdaFace Newsfeed
EdaFace Newsfeed EdaFace
EdaFace Newsfeed > Latest News > Security & Hacks > Chrome Warnings Were Not in Vain, Crypto Investors Are Victims
Security & Hacks

Chrome Warnings Were Not in Vain, Crypto Investors Are Victims

vitalclick
Last updated: August 30, 2024 5:50 pm
5 months ago
Share
SHARE

Recently Google We mentioned that a new 0-day vulnerability was discovered for Chrome. 0-day or zero-day vulnerabilities are “elite” vulnerabilities used by a small number of technically savvy attackers. They are usually sold on the deep web for thousands or even tens of thousands of dollars. And those who detect them only use them themselves to get even bigger loot.

Chrome Vulnerability and Crypto

We write at every opportunity that you should stay away from websites and applications that you do not trust. In fact, you should use proven paid antivirus software to ensure the security of your web traffic. Antivirus software does not always protect users, but it largely keeps you away from the traps that have emerged. A Prize Pool Worth 21 Million TL Awaits You from BinanceTR! Participating and winning has never been easier.. You can sign up to BinanceTR from this link. Get your first crypto!

A moment ago, Microsoft mentioned that the vulnerability we mentioned was used by North Korean attackers to target crypto investors.

“On August 19, 2024 Microsoft“We have identified a North Korean threat actor who has exploited a zero-day vulnerability in Chromium, identified as CVE-2024-7971, to gain remote code execution (RCE) capabilities. We assess with high confidence that the observed exploit of CVE-2024-7971 is attributable to a North Korean threat actor targeting the cryptocurrency industry for financial gain.”

Microsoft experts found that the vulnerability was used jointly by two groups, Diamond Sleet and Citrine Sleet. So what is the attack scenario? We see this in the details of the research.

“The observed zero-day exploit attack by Citrine Sleet used typical stages seen in browser exploit chains. First, the targets were targeted by Citrine Sleet’s controlled voy****club[.]space attack address. While we cannot currently confirm how targets were redirected, social engineering (redirecting to a link claiming to be a trading or crypto wallet app, etc.) is a common tactic used by Citrine Sleet. Once connected to a target web address, a zero-day RCE exploit for CVE-2024-7971 was presented.

“Once the RCE exploit was able to execute code in a sandboxed Chromium renderer process, shellcode containing a Windows sandbox escape exploit and the FudModule rootkit was downloaded and then loaded into memory. The sandbox escape exploit exploited CVE-38106, a vulnerability in the Windows kernel that Microsoft patched on August 13, 2024, prior to the North Korean threat actor discovering its activity.”

Google Chrome patched this vulnerability (August 21) and is expected to make a detailed statement within 60 days. Always keep your browser up to date and do not stay skeptical. North Korean attackers are now launching much more targeted attacks, and such vulnerabilities detected from scratch make their job easier. No comprehensive report has yet been published on the cryptocurrency investors victimized by the attackers thanks to this vulnerability. In addition, those who have not yet updated their systems continue to be potential targets.

Disclaimer: The information contained in this article does not contain investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should carry out their transactions in line with their own research.

You Might Also Like

Hot Development: More Than Just Cryptocurrency Sites Are in Danger

Ransomware Could Break Records!

FBI Releases 2023 Cryptocurrency Scam Report, Countries With the Most Losses

Cryptocurrency Exchange BingX Falls Victim of Hack Attack! $43 Million Stolen!

Notable Crypto Comment from a Famous Name: What to Expect in the US?

TAGGED:Security
Share This Article
Facebook Twitter Email Print
Previous Article Monero (XMR) Price Hints A 20% Surge Amid Bullish Reversal?
Next Article Are Altcoins Like BNB And Cardano Dead? Nicholas Merten Says ‘We’re In For Rough Ride’
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Crypto Live Widget

Follow for Live Updates
Subscribe to our newslettern

Get Newest Articles Instantly!

- Advertisement -
Ad imageAd image
Popular News
Cryptocurrency Regulation in Russia : Blockchain Development
Current Cryptocurrency Regulations in India
Explore Cryptocurrency Regulation in South Korea
2 Altcoins Win Trial
Claimed Bitcoin Inventor Craig Wright Gets Shocked in Court! His Assets Are Frozen

Company

  • Vision
  • Mission
  • LitePaper
  • Whitepaper
  • Core Values
  • Branding
  • Teams
  • Career Listing
  • FAQ
  • Welfare Donations

Products

  • EDA Token
  • Blockchain Literature
  • EdaFace Dex
  • EdaFace Mall
  • Listing Platforms
  • Newsfeed
  • NFT Marketplace
  • P2P Market
  • Scam Verification Centre
  • School of Crypto

Legal

  • Term of Use
  • Privacy Policy
  • Disclaimer
  • Listing T&C
  • Listing Platforms
  • Eda Token Policy

Always Stay Up to Date

Subscribe to our newsletter to get our newest articles instantly!

EdaFace

About US

EdaFace is a user interface aggregator that brings all the various functionalities of the crypto industry onto a single platform! You can advertise, launch and crowdfund your crypto project via EdaFace Launchpad and Newsfeed.

Contact us: support@edaface.com

Follow us

Instagram Twitter Facebook Telegram Youtube Linkedin

Copyright © 2022 – 2024. EdaFace is a product of Emerging Digital Age (EDA) Pty Ltd. All Rights Reserved.

Join Us!
Subscribe to our newsletter and never miss our latest news, podcasts etc..

Zero spam, Unsubscribe at any time.
EdaFace
Welcome Back!

Sign in to your account

Lost your password?