City
Epaper

2 N.Korean govt-backed hackers exploited Chrome bug: Google

By IANS | Updated: March 27, 2022 13:30 IST

New Delhi, March 27 Google has discovered that North Korean government-backed hackers are targeting news media, IT, cryptocurrency ...

Open in App

New Delhi, March 27 Google has discovered that North Korean government-backed hackers are targeting news media, IT, cryptocurrency and fintech industries in the US and globally.

The Google Threat Analysis Group (TAG) found that two distinct North Korean government-backed attacker groups were exploiting a remote code execution vulnerability in Chrome browser.

"We suspect that these groups work for the same entity with a shared supply chain, hence the use of the same exploit kit, but each operate with a different mission set and deploy different techniques," the company said in a blog post.

It is possible that other North Korean government-backed attackers have access to the same exploit kit, it added.

One campaign, consistent with 'Operation Dream Job', targeted over 250 individuals working for 10 different news media, domain registrars, web hosting providers and software vendors.

The targets received emails claiming to come from recruiters at Disney, Google and Oracle with fake potential job opportunities.

The emails contained links spoofing legitimate job hunting websites like Indeed and ZipRecruiter.

"Victims who clicked on the links would be served a hidden iframe that would trigger the exploit kit," said Google.

Another North Korean group, whose activity has been publicly tracked as 'Operation AppleJeus', targeted over 85 users in cryptocurrency and fintech industries leveraging the same exploit kit.A

This included compromising at least two legitimate fintech company websites and hosting hidden iframes to serve the exploit kit to visitors.

"In other cases, we observed fake websites already set up to distribute trojanised cryptocurrency applications hosting iframes and pointing their visitors to the exploit kit," Google informed.

Upon discovery, all identified websites and domains were added to 'Safe Browsing' to protect users from further exploitation.

"We also sent all targeted Gmail and Workspace users government-backed attacker alerts notifying them of the activity," said Google.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Tags: Google threat analysis groupusgoogleNew DelhiWord on macThe new delhi municipal councilWho dgDelhi south-westMicrosoft incUs google & youtubeSk dua
Open in App

Related Stories

CricketVirat Kohli Spotted at Delhi Airport Ahead of India's Tour of Australia, Video Goes Viral

InternationalUS Government Shutdown: US Embassy in India’s X Account to Pause Regular Updates Until Full Operations Resume

TechnologyGoogle Birthday Doodle: Search Engine Giant Brings Back 1998 Logo as It Turns 27 Today

CricketIND-W vs AUS-W, 3rd ODI: Australia Women Win Toss, Opt to Bat Against India in Series Decider; Check Playing XIs

CricketWhy Is India Women’s Cricket Team Wearing a Pink Jersey in IND-W vs AUS-W 3rd ODI 2025 Match?

Technology Realted Stories

TechnologyIndia aims 300 million tonnes of crude steel production capacity by 2030

TechnologyMpox spreading to more countries, 17 deaths in Africa in last 6 weeks, says WHO

TechnologyGovt committed to share best practices under Norway India Partnership Initiative: Health Secy

TechnologyUIDAI unveils ‘Aadhaar Vision 2032’ framework to strengthen digital identity through AI, advanced encryption

TechnologyNarayana Health’s UK expansion shows Bharat's growing capabilities: Piyush Goyal