Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026

Prediction markets are ditching the 'casino' label to become a regular part of how people track the news

May 2, 2026

Altura Enables On-chain Lending With AVLT on Morpho

May 2, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»Lazarus Group Exploits Google Chrome Flaw in New Campaign
Lazarus Group Exploits Google Chrome Flaw in New Campaign
Security

Lazarus Group Exploits Google Chrome Flaw in New Campaign

February 28, 2026No Comments2 Mins Read

A recently discovered cyber-attack by the notorious Lazarus Group, including its BlueNoroff subgroup, has exposed a new vulnerability in Google Chrome.

The group used a zero-day exploit to take complete control of infected systems, marking the latest in a long series of sophisticated campaigns from the North Korean-backed threat actor.

The campaign was uncovered when Kaspersky Total Security detected a new instance of the Manuscrypt malware on a personal computer in Russia.

Manuscrypt, a signature Lazarus tool, has been in use since at least 2013, appearing in over 50 documented campaigns targeting governments, financial institutions, cryptocurrency platforms and more. However, this case stood out as the group rarely targets individuals directly.

Zero-Day Exploit in Google Chrome Enables Full System Control

Further investigation traced the infection back to a deceptive website, detankzone[.]com, which posed as a legitimate decentralized finance (DeFi) game platform. Visitors to the site unknowingly triggered the exploit simply by accessing it through Chrome. The game, advertised as an NFT-based multiplayer online battle arena, was merely a facade, hiding malicious code that hijacked the user’s system via the browser.

The exploit, which targeted a newly introduced feature in Chrome’s V8 JavaScript engine, allowed attackers to bypass the browser’s security mechanisms and gain remote control over affected devices. Kaspersky researchers promptly reported the vulnerability to Google, which released a patch within two days.

Here are the key vulnerabilities at the heart of this campaign:

  • CVE-2024-4947: A flaw in Chrome’s new Maglev compiler that allows attackers to overwrite critical memory structures

  • V8 Sandbox Bypass: A second vulnerability enabled Lazarus to bypass Chrome’s memory protection features, executing arbitrary code

See also  New AppLite Malware Targets Banking Apps in Phishing Campaign

Read more on browser-focused attacks: Browser Phishing Threats Grew 198% Last Year

While Kaspersky adhered to responsible disclosure practices, Microsoft reportedly published a related report that missed the zero-day element of the campaign. This triggered Kaspersky to provide further details, emphasizing the gravity of the vulnerability and the need for users to update their browsers immediately.

As Lazarus continues to refine its methods, leveraging social engineering, zero-day exploits and legitimate-looking platforms, organizations and individuals alike must remain vigilant.

Image credit: Alberto Garcia Guillen / Shutterstock.com

Source link

Campaign Chrome exploits flaw Google Group Lazarus

Related Posts

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026

US seized $500M in Iranian crypto assets, Treasury secretary says

May 2, 2026

Wasabi Protocol drained for $4.5 million in apparent admin key compromise

May 2, 2026

Tax season fuels rise in crypto wallet scams, Kaspersky reports

May 2, 2026
Top Posts

Investigators Flag Coinbase Page Asking For Seed Phrases, Tool Removed

March 22, 2026

Circle’s Wild Stock Comeback Turns Stablecoins Into a Wall Street Talking Point

March 16, 2026

A new narrative for bitcoin that will last

May 2, 2026

Type above and press Enter to search. Press Esc to cancel.