Threat Advisory

Lazarus Group Deploys Manuscrypt Backdoor via Chrome Zero-Day Exploit

Threat: Vulnerability/Malware
Threat Actor Name: Lazarus Group
Threat Actor Type: State-Sponsored
Targeted Region: Global
Alias: Genie Spider, Labyrinth Chollima, UNC577, UNC2970, UNC4034, UNC4736, UNC4899, Zinc, DEV-0139, Diamond Sleet, Jade Sleet, TA404, ITG03, Hastati Group, Hidden Cobra, Black Alicanto, ATK 3, Dangerous Password,CryptoCore , Leery Turtle , CryptoMimic, Group 77, Whois Hacking Team, NewRomanic Cyber Army Team, Appleworm, APT-C-26, SectorA01, Guardians of Peace, Gods Apostles, Gods Disciples, TraderTraitor
Threat Actor Region: North Korea
Targeted Sector: Government & Defense, Finance & Banking, Technology & IT, Telecommunications, Education, Retail & E-Commerce
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Lazarus APT, a notorious and highly North Korean threat actor, has been active for over a decade and is known for its diverse range of cyberattacks. The group is responsible for several high-profile campaigns targeting governments, financial institutions, military contractors, and cryptocurrency platforms, among others. Their use of Manuscrypt, a backdoor malware, has been observed again in a campaign involving the exploitation of a zero-day vulnerability in Google Chrome CVE-2024-4947. This attack, which bypassed Chrome's sandboxing mechanism, targeted individuals with a deceptive game website designed to lure victims into downloading malware.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Lazarus APT, a notorious and highly North Korean threat actor, has been active for over a decade and is known for its diverse range of cyberattacks. The group is responsible for several high-profile campaigns targeting governments, financial institutions, military contractors, and cryptocurrency platforms, among others. Their use of Manuscrypt, a backdoor malware, has been observed again in a campaign involving the exploitation of a zero-day vulnerability in Google Chrome CVE-2024-4947. This attack, which bypassed Chrome's sandboxing mechanism, targeted individuals with a deceptive game website designed to lure victims into downloading malware.[emaillocker id="1283"]

The attack begins with a Google Chrome zero-day exploit, delivered through a seemingly innocent website promoting a decentralized finance game. The exploit takes advantage of two critical vulnerabilities in the Chrome V8 engine: the first, CVE-2024-4947, enables attackers to bypass memory protections and achieve remote code execution by exploiting flaws in the new Maglev compiler. The second vulnerability involves a bypass of the V8 heap sandbox, which allows attackers to read and write memory outside of the V8 sandbox, facilitating further exploitation. Once inside the system, attackers use memory manipulation techniques to gain control over the victim’s machine, deploying the Manuscrypt Backdoor as part of their payload. This backdoor enables persistent access and advanced reconnaissance capabilities, furthering the attackers’ objectives.

In conclusion, Lazarus APT's use of social engineering tactics, combined with the advanced zero-day exploit CVE-2024-4947 targeting Google Chrome, highlights the increasing complexity of modern threats. Their ability to craft convincing decoy websites and deploy multi-stage attacks, including the deployment of the Manuscrypt Backdoor, underscores the importance of timely vulnerability patching and the need for continued vigilance in both enterprise and personal security practices. The backdoor's capability to establish persistent access and facilitate advanced reconnaissance further amplifies the threat posed by such campaigns. This serves as a reminder of the ever-evolving tactics and tools employed by advanced persistent threat groups to compromise sensitive targets across multiple industries.

 

THREAT PROFILE:

Tactic Technique Id Technique
Initial Access T1566 Phishing
T1190 Exploit Public-Facing Application
Execution T1203 Exploitation for Client Execution
T1204 User Execution
Privilege Escalation T1068 Exploitation for Privilege Escalation
Defense Evasion T1027 Obfuscated Files or Information
Discovery T1082 System Information Discovery
Collection T1005 Data from Local System
T1056 Input Capture
Command and Control T1071 Application Layer Protocol
T1105 Ingress Tool Transfer
 Exfiltration T1041 Exfiltration Over C2 Channel
Impact T1485 Data Destruction

 

RECOMMENDATIONS:

  • We strongly recommend you update Google Chrome for Linux to version 125.0.6422.60 and for Windows, macOS to version 125.0.6422.60/.61.


REFERENCES:

The following reports contain further technical details:
https://thehackernews.com/2024/10/lazarus-group-exploits-google-chrome.html

[/emaillocker]
crossmenu