📈 Get daily crypto insights that make you smarter about your money

North Korean Hackers Weaponize Chromium Zero-Day in Targeted Cryptocurrency Theft Campaign

Microsoft has disclosed a sophisticated cyberattack campaign in which North Korean threat actors exploited a zero-day vulnerability in the Chromium web browser to target cryptocurrency users worldwide. The campaign, attributed to a group Microsoft tracks as Citrine Sleet — also known as AppleJeus and Hidden Cobra — leverages CVE-2024-7971, a high-severity remote code execution flaw in the V8 JavaScript and WebAssembly engine that powers Google Chrome, Microsoft Edge, and other Chromium-based browsers.

The Threat Landscape

The vulnerability exists in Chromium versions prior to 128.0.6613.84, which began rolling out on August 21, 2024. Microsoft’s Security Response Center discovered the active exploitation and notified Google on August 19. Google rated the severity as high, given that the flaw enables remote execution of arbitrary code on a victim’s machine simply by visiting a crafted webpage.

Citrine Sleet is financially motivated and linked to North Korea’s Bureau 121, part of the military’s Reconnaissance General Bureau. The group has a well-documented history of targeting cryptocurrency exchanges, individual traders, and DeFi platforms. Their operational sophistication matches that of advanced persistent threat groups employed by other nation-states, but their financial objectives align directly with Pyongyang’s need to generate foreign currency through cybercrime.

Core Principles

The attack chain begins with social engineering. Citrine Sleet operates fake cryptocurrency trading platforms and sends fraudulent job application lures to targets in the blockchain and cryptocurrency industry. Victims who interact with these lures are redirected to attacker-controlled domains that exploit the Chromium vulnerability to install a rootkit called FudModule on the target system.

FudModule operates entirely in memory, making it difficult for traditional antivirus solutions to detect. The rootkit also attempts to exploit CVE-2024-38106, a Windows kernel privilege escalation vulnerability, to escape browser sandbox protections. Once sandbox escape is achieved, the malware gains system-level access and can intercept cryptocurrency wallet credentials, private keys, and seed phrases.

The multi-stage nature of this attack is instructive. It combines a browser exploit with an operating system privilege escalation and a fileless rootkit — a trifecta that represents the cutting edge of offensive cyber operations.

Tooling and Setup

Defending against this type of campaign requires a layered security approach. Browser updates are the first and most critical line of defense. Users should verify they are running Chromium 128.0.6613.84 or later. Automatic browser updates should be enabled, and users who have disabled them for any reason should re-enable them immediately.

Hardware wallets provide essential protection against credential theft. Even if malware compromises a user’s operating system, private keys stored on a hardware wallet like a Ledger or Trezor never leave the device. Transaction signing occurs on the hardware itself, rendering key-logging and memory-scraping attacks ineffective.

Email and messaging hygiene is equally important. Citrine Sleet’s social engineering lures — fake job offers, fraudulent trading platforms — are designed to appear legitimate. Verifying the authenticity of unsolicited communications before clicking links or downloading files is a non-negotiable practice.

Ongoing Vigilance

The Citrine Sleet campaign underscores a broader trend: nation-state actors are increasingly targeting the cryptocurrency ecosystem as a revenue source. North Korea alone has been linked to billions of dollars in cryptocurrency thefts over the past several years, and the sophistication of their operations continues to advance.

For organizations in the crypto space, this means investing in endpoint detection and response solutions capable of detecting fileless malware. Network monitoring tools that flag unusual outbound connections to suspicious domains can catch command-and-control traffic before exfiltration completes.

Individual users should regularly review their browser extensions, remove any they do not recognize, and monitor their wallet transaction history for unauthorized activity. With Bitcoin trading above $59,000 and the total crypto market cap exceeding $2 trillion, the incentives for state-sponsored cybercrime will only intensify.

Final Takeaway

The convergence of nation-state capabilities with financially motivated cryptocurrency targeting represents a new frontier in cybersecurity. CVE-2024-7971 is not just a browser bug — it is a window into how the most sophisticated threat actors on the planet view the crypto ecosystem. Update your browser, use a hardware wallet, and treat every unsolicited link as a potential weapon.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

25 thoughts on “North Korean Hackers Weaponize Chromium Zero-Day in Targeted Cryptocurrency Theft Campaign”

  1. CVE-2024-7971 in Chromium V8 and DPRK is actively exploiting it. Update your browser right now if you havent since August 21

    1. updated chrome the same day this dropped. V8 RCE with no user interaction beyond a page visit is nightmare fuel for anyone trading from a browser

      1. Updated my browser immediately after reading this. The fact that this affects all Chromium-based browsers means most crypto traders are at risk if they haven’t updated since August.

  2. CVE-2024-7971 gave DPRK remote code execution from just loading a webpage. anyone with a browser wallet and outdated Chrome was one click away from funding weapons programs

    1. Yejin O. the V8 engine exploit chain was so clean they didnt even need user interaction beyond visiting a page. hardware wallets are the only real defense against nation state browser exploits

  3. Citrine Sleet has been at this for years. AppleJeus was their fake crypto exchange tool from 2018. Same playbook, better delivery.

    1. Kwame AppleJeus to Chromium zero-day is quite the upgrade in 6 years. they went from building fake exchanges to exploiting browser engines. the skill gap closed fast

    2. AppleJeus shipped as a fake trading app back in 2018 if I remember right. same social engineering, except now they buy zero days instead of building malware. cheaper per target apparently

      1. commodity stealer kits cost pennies while a chromium 0day runs seven figures. wrapping it in a fake trading app is just cost efficiency on their end

    1. neon_drift RCE from just visiting a page is why browser-based wallets are a liability. metamask running in the same process as a compromised V8 engine is asking for trouble. extension wallets need separate process isolation

      1. Rohit V. extension wallets in the same process as V8 is exactly why i moved to a dedicated signing device. metamask in a compromised browser process is game over

      2. separate process isolation would wreck extension wallet ux overnight. the actual fix is hardware signing, a compromised browser should never be enough to move funds alone

        1. agreed. a compromised browser should never be enough to move funds. airgapped signing makes a chromium 0day about as dangerous as a notepad app

    1. Marcus the geopolitical angle gets lost because people focus on the CVE. bureau 121 has a staff of maybe 6000+ people. crypto theft funds an estimated 50% of their weapons programs. every wallet drained is literally a missile component

    2. the geopolitics angle gets underreported. every wallet drained is literally funding weapons programs. not just some random hack

      1. Bureau 121 funding nuclear weapons with stolen crypto – that’s the real story here. Every drained wallet is literally helping build missiles.

        1. 210924 bureau 121 funding missiles with drained crypto wallets and people still keep their seed phrases in google drive. the threat model is literally nation state and people act like its script kiddies

        2. UN estimates put their crypto theft haul north of 3B by then. Every drained hot wallet is a missile component, and people still open fake recruiter PDFs.

          1. and every estimate is a floor because exchanges settle these quietly and never publish postmortems. no public incident data means the 3B figure is probably conservative

  4. Bureau 121 has been upgrading from fake exchanges in 2018 to browser zero-days by 2024. the operational sophistication growth is terrifying

  5. The fact that they’re using V8 RCE from just visiting a page shows how sophisticated these attacks have become. Hardware wallets are no longer just for security maximalists.

  6. chrome 127 with a hot wallet connected is basically an open door with a welcome mat. the patch landed august 21, update your browser people

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$77,344.00+0.3%ETH$2,508.35-0.6%SOL$101.21-0.5%BNB$720.95-1.2%XRP$1.36-0.5%ADA$0.2090+0.7%DOGE$0.0845-0.4%DOT$1.02-0.8%AVAX$7.43+0.6%LINK$11.43-0.8%UNI$6.35+0.6%ATOM$1.61-0.5%LTC$55.03+2.3%ARB$0.1392-1.2%NEAR$2.36-0.2%FIL$0.9940+23.5%SUI$0.7225+0.0%BTC$77,344.00+0.3%ETH$2,508.35-0.6%SOL$101.21-0.5%BNB$720.95-1.2%XRP$1.36-0.5%ADA$0.2090+0.7%DOGE$0.0845-0.4%DOT$1.02-0.8%AVAX$7.43+0.6%LINK$11.43-0.8%UNI$6.35+0.6%ATOM$1.61-0.5%LTC$55.03+2.3%ARB$0.1392-1.2%NEAR$2.36-0.2%FIL$0.9940+23.5%SUI$0.7225+0.0%
Scroll to Top