Google says it acted to mitigate threats from two North Korean government-backed attackers. The attacks targeted U.S. based organizations spanning news media, IT, cryptocurrency, and fintech industries. The earliest evidence we have of this exploit kit being actively deployed is January 4, 2022, researchers say. The exploit kit is fashioned as a multi-stage infection chain that involves embedding the attack code within hidden internet frames on both compromised websites as well as rogue websites under their control. Google’s TAG, which discovered the intrusions on February 10, noted that it was “unable to recover any of the stages””]
Source: https://thehackernews.com/2022/03/north-korean-hackers-exploited-chrome.html