The Crypto Game of Lazarus APT: Investors vs. Zero-days


On May 13, 2024, Kaspersky consumer-grade product Kaspersky Total Security detected a new Manuscrypt infection on the personal computer of a person living in Russia. Since Lazarus rarely attacks individuals, this piqued Kaspersky researchers interest and they decided to take a closer look.

The researchers discovered that prior to the detection of Manuscrypt, Kaspersky technologies also detected exploitation of the Google Chrome web browser originating from the website detankzone[.]com. On the surface, this website resembled a professionally designed product page for a decentralized finance (DeFi) NFT-based (non-fungible token) multiplayer online battle arena (MOBA) tank game, inviting users to download a trial version. But that was just a disguise. Under the hood, this website had a hidden script that ran in the user’s Google Chrome browser, launching a zero-day exploit.

Read more…
Source: Kaspersky


Sign up for our Newsletter


Related:

  • France probes compromise of gov messaging platform after account hijack

    June 9, 2026

    French officials are investigating a compromise of the government’s encrypted messaging service Tchap after attackers hijacked an account and gained access to public chat rooms. The incident came to light on June 7 when France’s National Cybersecurity Agency (ANSSI) detected suspicious activity on Tchap, the government’s homegrown messaging service used across ministries and public sector organizations. The French ...

  • CISA gives US federal agencies three days to fix a VPN bug under attack by a ransomware gang

    June 9, 2026

    A ransomware group is actively exploiting an unpatched flaw in security tools used across the U.S. federal government, prompting the U.S. cybersecurity agency CISA to order all civilian agencies to remediate the vulnerability by end of day Wednesday. Cybersecurity firm Check Point Software said the bug affects several of its remote access tools, firewalls, and VPNs, which act as ...

  • Chrome’s zero-day Whac-A-Mole continues with fifth exploited bug of the year

    June 9, 2026

    Google has fixed its fifth actively exploited Chrome zero-day of 2026, and this one earned its finder a $55,000 bounty. The flaw, tracked as CVE-2026-11645, is an out-of-bounds memory access bug in Chrome’s V8 JavaScript engine. Google confirmed that the vulnerability is being exploited in the wild, but has disclosed little beyond the bare technical details. Read ...

  • WhatsApp says it caught new spyware attacks linked to NSO Group in violation of court order

    June 8, 2026

    WhatsApp said that it disrupted a new hacking campaign linked to NSO Group, a spyware maker that has been ensnared in countless cases of abuse all over the world. The messaging app maker accused NSO of violating an earlier court order that bars the company from targeting WhatsApp and its users with its spyware, and is seeking to ...

  • Microsoft’s open source tools were hacked to steal passwords of AI developers

    June 8, 2026

    Microsoft has cut off access to dozens of its open source projects hosted on GitHub as it investigates how hackers apparently breached the projects and injected password-stealing malware into the code. Many of the affected projects relate to Microsoft’s cloud service Azure and other tools used by developers to code with AI development apps, such as ...

  • From cause to cash: a cross-border look at hacktivist activity

    June 8, 2026

    While tracking the activities of 4BID Kaspersky researchers uncovered a new string of campaigns that appear to be the work of several interconnected actors. While politically motivated groups generally limit their scope to specific nations – for 4BID and its peers, primarily Russian and occasionally Belarusian organizations – the latest findings reveal a shift. The actual ...