#WizardOpium

Incident/Operation

2019-11-01 • Chrome 0-day exploit CVE-2019-13720 used in Operation WizardOpium

WizardOpium is the name assigned to 2019 watering-hole attacks that exploited the then-zero-day Chrome vulnerability CVE-2019-13720. Attackers injected JavaScript into a Korean-language news portal, profiled visitors, and redirected selected systems to an exploit landing page, enabling code execution through the browser flaw. The responsible actor remains unresolved: weak code similarities to Lazarus could have been a false flag, and the profile of the targeted site resembled other activity in which attackers planted deceptive attribution signals.

Tagged Reports

« Back