Windows, Chrome Zero-Days Chained in Operation WizardOpium Attacks

[correlate]

Level 18
Thread author
Top Poster
Well-known
May 4, 2019
801
Zero-day vulnerabilities in Google Chrome and Microsoft Windows were used to download and install malware onto Windows computers that visited a Korean-language news portal.
A zero-day vulnerability is one that is known, but not patched by the developers in charge of patching the vulnerability. These zero-day vulnerabilities are particularly dangerous as they can be used by state-sponsored attackers to perform malicious activity on vulnerable devices.
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
It was patched already, as mentioned by @upnorth, but even before that, it required a prior infection in order to work.
"The one caveat is that to exploit the flaw, an attacker would need to have previously compromised the system using another vulnerability "
So clean computers were not at risk; only previously infected ones were. It smells like another episode in the series of targeted attacks against South Korean diplomats.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top