EXECUTIVE SUMMARY:
Lazarus APT, a notorious and highly North Korean threat actor, has been active for over a decade and is known for its diverse range of cyberattacks. The group is responsible for several high-profile campaigns targeting governments, financial institutions, military contractors, and cryptocurrency platforms, among others. Their use of Manuscrypt, a backdoor malware, has been observed again in a campaign involving the exploitation of a zero-day vulnerability in Google Chrome CVE-2024-4947. This attack, which bypassed Chrome's sandboxing mechanism, targeted individuals with a deceptive game website designed to lure victims into downloading malware.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Lazarus APT, a notorious and highly North Korean threat actor, has been active for over a decade and is known for its diverse range of cyberattacks. The group is responsible for several high-profile campaigns targeting governments, financial institutions, military contractors, and cryptocurrency platforms, among others. Their use of Manuscrypt, a backdoor malware, has been observed again in a campaign involving the exploitation of a zero-day vulnerability in Google Chrome CVE-2024-4947. This attack, which bypassed Chrome's sandboxing mechanism, targeted individuals with a deceptive game website designed to lure victims into downloading malware.[emaillocker id="1283"]
The attack begins with a Google Chrome zero-day exploit, delivered through a seemingly innocent website promoting a decentralized finance game. The exploit takes advantage of two critical vulnerabilities in the Chrome V8 engine: the first, CVE-2024-4947, enables attackers to bypass memory protections and achieve remote code execution by exploiting flaws in the new Maglev compiler. The second vulnerability involves a bypass of the V8 heap sandbox, which allows attackers to read and write memory outside of the V8 sandbox, facilitating further exploitation. Once inside the system, attackers use memory manipulation techniques to gain control over the victim’s machine, deploying the Manuscrypt Backdoor as part of their payload. This backdoor enables persistent access and advanced reconnaissance capabilities, furthering the attackers’ objectives.
In conclusion, Lazarus APT's use of social engineering tactics, combined with the advanced zero-day exploit CVE-2024-4947 targeting Google Chrome, highlights the increasing complexity of modern threats. Their ability to craft convincing decoy websites and deploy multi-stage attacks, including the deployment of the Manuscrypt Backdoor, underscores the importance of timely vulnerability patching and the need for continued vigilance in both enterprise and personal security practices. The backdoor's capability to establish persistent access and facilitate advanced reconnaissance further amplifies the threat posed by such campaigns. This serves as a reminder of the ever-evolving tactics and tools employed by advanced persistent threat groups to compromise sensitive targets across multiple industries.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1566 | Phishing |
| T1190 | Exploit Public-Facing Application | |
| Execution | T1203 | Exploitation for Client Execution |
| T1204 | User Execution | |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| Discovery | T1082 | System Information Discovery |
| Collection | T1005 | Data from Local System |
| T1056 | Input Capture | |
| Command and Control | T1071 | Application Layer Protocol |
| T1105 | Ingress Tool Transfer | |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
| Impact | T1485 | Data Destruction |
RECOMMENDATIONS:
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/10/lazarus-group-exploits-google-chrome.html