Microsoft cyber security researchers have discovered a zero-day vulnerability in a Chromium engine that powers browsers such as Chrome. The vulnerability was exploited by a North Korean hacking group called Citrine Sleet to specifically target cryptocurrency users. Citrine Sleet uses rootkit malicious software called FudModule to trick users into downloading malicious software or weaponized add-ons by creating fake cryptocurrency trading platform websites.