Cryptocurrency

NFT game under threat: Lazarus Group unveils new hack

Cet article peut contenir des liens d'affiliation. En savoir plus

The North Korean hacker group Lazarus is making headlines again with a daring cyberattack. This time, they used a fake blockchain-based video game as bait to infiltrate cryptocurrency wallets. At the heart of this attack is a vulnerability in the Google Chrome browser, allowing the group to access sensitive user information. This article explores the aspects of this attack and its implications for the NFT gaming ecosystem. The Persistent Threat of Lazarus Lazarus is a notorious group whose activities in the cryptocurrency space have intensified in recent years. Between 2020 and 2023, this group was responsible for more than 25 attacks targeting blockchain protocols and cryptocurrency exchanges. Their latest operation, revealed on October 23 by Kaspersky, once again demonstrated their ability to innovate in their attack techniques. A Blockchain Video Game as Bait To trap their victims, the hackers created a fake game calledDetankzone

, based on the concept of NFTs. This MOBA was designed to appeal to online gaming and cryptocurrency enthusiasts. The group even set up a professional website offering users the opportunity to download a beta version of the game.

At first glance, it would appear that the malware was embedded in this beta version. However, a thorough analysis by Kaspersky researchers revealed that the real danger lay elsewhere. The game code itself was authentic, having been stolen from a pre-existing project, DeFiTankLand. An Effective Diversion Strategy In this case, the game was merely a pretext to distract users from the real threat: the website dedicated to the game. The hackers exploited a zero-day vulnerability.in Google Chrome to infiltrate victims’ machines without attracting their attention. The flaw allowed malicious code to be executed in the background while browsing the fake site.

A LIRE  Bitcoin October 25: Is BTC Repeating 2021 Bullish Surge Pattern?

Once the vulnerability was exploited, the malicious script bypassed security protections, giving the Lazarus group full access to users’ cryptocurrency wallets. This sophisticated mechanism demonstrates the high level of ingenuity behind this attack.

The cybersecurity community’s reaction Following the discovery of this flaw, Kaspersky teams alerted Google, which quickly deployed a patch to address the vulnerability. However, this attack highlights the random behavior of hackers and raises concerns about the continued security of NFT game users. Google’s swift response does not negate the potential dangers for those interacting with these types of games. Lazarus: A Sprawling OrganizationIt’s important to note that the attack was not directly carried out by Lazarus, but by a subgroup known as BlueNoroff. The latter is also linked to the North Korean government and aims to extort funds from cryptocurrency users.

The trend observed here is alarming: until now, Lazarus has primarily targeted financial institutions or high-net-worth individuals, but this attack indicates a shift toward broader targets, including less wealthy users. This diversified strategy could lead to an increased number of vulnerable victims. In this context, awareness of the risks associated with NFT games becomes crucial. Users must be cautious of new applications that can mask significant threats. This is a reality that must now be addressed in the dynamic world of blockchain technologies. Loss Update Recently, it was discovered that collaborative efforts between stakeholders in the cryptocurrency industry had resulted in the recovery of stolen funds. In September, a $5 million freeze was imposed against Lazarus, but the extent of the funds misappropriated by the group remains unclear.To date, Lazarus has stolen billions of dollars and, without concrete preventative measures, will continue to wreak havoc in the cryptocurrency space. This is a call to action to strengthen cybersecurity measures within all platforms, where every user must remain vigilant.

A LIRE  Apple opts for discretion by removing cryptocurrency apps in Korea

https://www.youtube.com/watch?v=Q2AbySSPadw

⚠️ Information réglementaire. Ce contenu est publié à titre purement informatif et pédagogique. Il ne constitue ni un conseil en investissement, ni une recommandation personnalisée, ni une incitation à investir. Investir comporte un risque de perte en capital et les performances passées ne préjugent pas des performances futures. Consultez un conseiller en investissement financier (CIF) agréé avant toute décision.
🔗 Transparence. Cette page peut contenir des liens affiliés : un achat effectué via ces liens peut nous rémunérer, sans coût supplémentaire pour vous. Cela n’influence pas notre analyse.