Citrine sleet targets cryptocurrency platforms with newly discovered security vulnerabilities
A recently patched security flaw in Google Chrome and other Chromium-based web browsers was exploited by North Korean threat actors as a zero-day vulnerability in a campaign aimed at deploying the FudModule rootkit. This development highlights the persistent efforts of North Korean state-sponsored groups to exploit vulnerabilities in Windows systems.
The activity, detected by Microsoft on 19 August 2024, has been attributed to a threat actor known as Citrine Sleet, a sub-group within the notorious Lazarus Group. Also referred to as AppleJeus, Labyrinth Chollima, Nickel Academy, and UNC4736, Citrine Sleet is known for targeting financial institutions and individuals involved in cryptocurrency, primarily for financial gain.
Citrine Sleet’s attacks involve sophisticated social engineering tactics, including the creation of fake websites that mimic legitimate cryptocurrency trading platforms. These websites are designed to trick users into installing weaponised cryptocurrency wallets or trading applications, ultimately facilitating the theft of digital assets.
The zero-day exploit in question involves CVE-2024-7971, a high-severity type confusion vulnerability in the V8 JavaScript and WebAssembly engine. This flaw could allow attackers to achieve remote code execution (RCE) in the sandboxed Chromium renderer process. Google patched this vulnerability in updates released last week.
This is the third type confusion bug in V8 that Google has addressed this year, following CVE-2024-4947 and CVE-2024-5274. The attacks leveraging CVE-2024-7971 appear to have targeted victims via a malicious website named voyagorclub[.]space, likely through social engineering techniques.
The exploit chain involves the retrieval of shellcode containing a Windows sandbox escape exploit (CVE-2024-38106) and the FudModule rootkit, which grants attackers admin-to-kernel access on Windows systems, allowing them to perform direct kernel object manipulation.
CVE-2024-38106, a Windows kernel privilege escalation vulnerability, was among the six actively exploited security flaws Microsoft fixed in its August 2024 Patch Tuesday update. However, Citrine Sleet’s exploitation of the flaw occurred after the patch was released, suggesting either independent discovery by separate threat actors or shared knowledge of the vulnerability.
CVE-2024-7971 is the third vulnerability that North Korean hackers have used this year to drop the FudModule rootkit, following CVE-2024-21338 and CVE-2024-38193, both of which are privilege escalation flaws in built-in Windows drivers.
Microsoft emphasised that the CVE-2024-7971 exploit chain relies on multiple components, and the attack chain can be thwarted if any of these components are blocked. The company underscores the importance of keeping systems up to date and employing security solutions that provide unified visibility across the cyberattack chain to detect and block malicious activity following exploitation.

