A North Korean hacking group exploited a previously unknown vulnerability in Google Chrome to target cryptocurrency organisations. The flaw, CVE-2024-7971, enabled remote code execution. Google released a fix on August 21, 2024. The hackers used social engineering tactics, directing victims to a malicious domain, which led to subsequent Windows kernel exploit deployment.