The North Korean hacker group Lazarus used a zero-day vulnerability in the Google Chrome browser to install spyware through the fake blockchain game DeTankZone (or DeTankWar).
Kaspersky Labs analysts discovered the exploit in May 2024 and notified Google, after which the vulnerability was fixed.
The game, promoted on LinkedIn and X platforms, offered NFT tanks for participation in battles, but even those who did not download the game could be affected through an infected site.
Lazarus used the Manuscrypt malware to exploit the vulnerability in the V8 JavaScript engine. This is already the seventh such vulnerability detected in Chrome in 2024.