The Lazarus cybercrime gang, a North Korean state-sponsored hacking group, is using a fake game to target cryptocurrency users.
The gang rebranded a DeFi game called DeFiTankLand into DeTankZone and used it to exploit vulnerabilities in the Chrome browser.
The vulnerabilities allowed the hackers to steal sensitive data such as cookies, tokens, browsing history, and saved passwords from the victim's device.
The flaw in Chrome's JavaScript engine was discovered in mid-May 2024 and Google released a fix two weeks later.