North Korean government-backed hackers were recently detected by Google’s Threat Analysis Group attempting to exploit a zero-day vulnerability in Google Chrome, gaining access to people’s devices. Since then, the corporation has patched the security hole.
Adam Weidemann, Director of Engineering at Google, claimed in an official blog post that the weakness has been exploited since January 4th. Over the course of weeks, the bug was used for both intelligence and financial attacks, according to the post.
Operation Dream Job and Operation AppleJeus were the two groups’ code names, and they were both aimed “U.S. based organizations spanning news media, IT, cryptocurrency and fintech industries.”
The groups took use of CVE-2022-0609, a Chrome use-after-free flaw. The flaw allows hackers to insert malicious code into unprotected memory locations, allowing them to execute malware remotely.
Since then, the company has released a vulnerability patch for Chrome update version 98.0.4758.102. However, according to Weidemann, the gangs spent weeks between the 4th of January and the 14th of February carrying out many covert strikes in various phases, allowing them to obscure their footprints.
Weidemann wrote that the groups were “careful to protect their exploits … [they] deployed multiple safeguards to make it difficult for security teams to recover any of the stages.”
The units are thought to have been formed by North Korea’s dictatorial dictatorship to carry out actions to improve the country’s government’s resources.
Weidemann went on to say, “We suspect that these groups work for the same entity with a shared supply chain, hence the use of the same exploit kit, but each operates with a different mission set and deploys different techniques.
It is possible that other North Korean government-backed hackers have access to the same exploit kit.”
According to Google, it was not the only corporation targeted in the attacks, “Although we recovered a Chrome RCE, we also found evidence where the attackers specifically checked for visitors using Safari on macOS or Firefox (on any OS) and directed them to specific links on known exploitation servers.”
Weidemann also stated that Google places a strong priority on user privacy and security. He expressed himself as follows, “As part of our efforts to combat serious threat actors, we use the results of our research to improve the safety and security of our products.
We encourage any potential targets to enable Enhanced Safe Browsing for Chrome and ensure that all devices are updated.”
To read our blog on “Head of Lapsus$ hacking gang is a UK teen, Investigators said,” click here.
