{"id":69023,"date":"2025-03-31T11:36:06","date_gmt":"2025-03-31T03:36:06","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=69023"},"modified":"2025-03-31T11:36:08","modified_gmt":"2025-03-31T03:36:08","slug":"hackers-using-secret-method-to-attack-chrome-kaspersky-finds","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2025\/03\/31\/hackers-using-secret-method-to-attack-chrome-kaspersky-finds\/","title":{"rendered":"Hackers using secret method to attack Chrome, Kaspersky finds"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Kaspersky has identified and helped patch a sophisticated zero-day vulnerability in Google Chrome (CVE-2025-2783) that allowed attackers to bypass the browser\u2019s sandbox protection system. The exploit, discovered by Kaspersky\u2019s Global Research and Analysis Team (GReAT), required no user interaction beyond clicking a malicious link and demonstrated exceptional technical complexity. Kaspersky researchers have been acknowledged by Google for discovering and reporting this vulnerability.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In mid-March 2025,&nbsp;Kaspersky&nbsp;detected a wave of infections triggered when users clicked personalized phishing links delivered via email. After clicking, no additional action was needed to compromise their systems. Once&nbsp;Kaspersky\u2019s analysis confirmed that the&nbsp;exploit&nbsp;leveraged a previously unknown vulnerability in the latest version of Google&nbsp;Chrome,&nbsp;Kaspersky&nbsp;swiftly alerted Google\u2019s security team. A security patch for the vulnerability was released on March 25, 2025.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Kaspersky&nbsp;researchers dubbed the campaign \u201cOperation ForumTroll\u201d, as attackers sent personalized phishing emails inviting recipients to the \u201cPrimakov Readings\u201d forum. These lures targeted media outlets, educational institutions, and government organizations in Russia. The malicious links were extremely short-lived to evade detection, and in most cases ultimately redirected to the legitimate website for \u201cPrimakov Readings\u201d once the&nbsp;exploit&nbsp;was taken down.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The&nbsp;zero-day&nbsp;vulnerability in&nbsp;Chrome&nbsp;was only part of a chain that included at least two exploits: a still-unobtained remote code execution (RCE)&nbsp;exploit&nbsp;that apparently launched the attack, while the sandbox escape discovered by&nbsp;Kaspersky&nbsp;constituted the second stage. Analysis of the malware\u2019s functionality suggests the operation was designed primarily for espionage. All evidence points to an Advanced Persistent Threat (APT) group.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThis vulnerability stands out among the dozens of zero-days we\u2019ve discovered over the years,\u201d said Boris Larin, principal security researcher at Kaspersky GReAT. \u201cThe exploit bypassed Chrome\u2019s sandbox protection without performing any obviously malicious operations \u2013 it\u2019s as if the security boundary simply didn\u2019t exist. The technical sophistication displayed here indicates development by highly skilled actors with substantial resources. We strongly advise all users to update their Google Chrome and any Chromium-based browser to the latest version to protect against this vulnerability.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Google has credited&nbsp;Kaspersky&nbsp;for uncovering and reporting the issue, reflecting the company\u2019s ongoing commitment to collaboration with the global cybersecurity community and ensuring user safety.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Kaspersky&nbsp;continues to investigate Operation ForumTroll. Further details, including a technical analysis of the exploits and malicious payload, will be released in a forthcoming report once Google&nbsp;Chrome&nbsp;user security is assured. Meanwhile, all&nbsp;Kaspersky&nbsp;products detect and protect against this&nbsp;exploit&nbsp;chain and associated malware, ensuring users are shielded from the threat.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Kaspersky&nbsp;Next EDR Expert, a core component of the comprehensive&nbsp;Kaspersky&nbsp;Next XDR (Extended Detection and Response) Expert platform, played a crucial role in detecting a wave of infections caused by previously unknown, highly&nbsp;sophisticated&nbsp;malware. Our&nbsp;exploit&nbsp;detection and protection technologies swiftly identified a&nbsp;zero-day&nbsp;exploit&nbsp;before it became publicly known, enabling us to thoroughly analyze its behavior and impact.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This discovery follows&nbsp;Kaspersky&nbsp;GReAT\u2019s previous identification of another&nbsp;Chrome&nbsp;zero-day&nbsp;(CVE-2024-4947), which was exploited last year by the Lazarus APT group in a cryptocurrency theft campaign. In that case,&nbsp;Kaspersky&nbsp;researchers found a type confusion bug in Google\u2019s V8 JavaScript engine that enabled attackers to bypass security features through a fake cryptogame website.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To safeguard against&nbsp;sophisticated&nbsp;attacks&nbsp;like these,&nbsp;Kaspersky&nbsp;security experts recommend implementing these key protective measures:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Ensure timely software updates: Regularly patch your operating system and browsers\u2014especially Google\u00a0Chrome\u2014so attackers cannot\u00a0exploit\u00a0newly discovered vulnerabilities.<br><\/li>\n\n\n\n<li>Adopt a multi-layered security approach: Along with endpoint protection, consider solutions like\u00a0Kaspersky\u00a0Next XDR Expert\u00a0that leverage AI\/ML to correlate data from multiple sources and automate detection and response against advanced threats and APT campaigns.<\/li>\n\n\n\n<li>Leverage threat intelligence services: Up-to-date, contextual information\u2014such as\u00a0Kaspersky\u00a0Threat Intelligence\u2014helps you stay informed about emerging\u00a0zero-day\u00a0exploits and the latest attacker techniques.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>The exploit, discovered by Kaspersky\u2019s Global Research and Analysis Team (GReAT), required no user interaction beyond clicking a malicious link and demonstrated exceptional technical complexity. Kaspersky researchers have been acknowledged by Google for discovering and reporting this vulnerability.<\/p>\n","protected":false},"author":6,"featured_media":57010,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[286,101,54,2103],"class_list":["post-69023","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-it-security","tag-kaspersky","tag-security","tag-security-breach"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/69023","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=69023"}],"version-history":[{"count":1,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/69023\/revisions"}],"predecessor-version":[{"id":69024,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/69023\/revisions\/69024"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/57010"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=69023"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=69023"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=69023"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}