Security Agency: Suspected North Korean hacker group collaborates to attack cryptocurrency companies to steal keys and cloud assets

By: rootdata|2026/03/09 12:45:45
0
Share
copy

Security research organization Ctrl-Alt-Intel disclosed that a group of hackers suspected to be linked to North Korea has targeted staking platforms, exchange software vendors, and cryptocurrency exchanges.

The attackers exploited the React2Shell vulnerability (CVE-2025-55182) and compromised cloud environments using obtained AWS access credentials, enumerating resources such as S3, EC2, RDS, EKS, and ECR, and extracting keys and credentials from Secrets Manager, Terraform files, Kubernetes configurations, and Docker containers. Researchers stated that the attackers downloaded 5 Docker images and stole source code, including components related to ChainUp clients.

The attack infrastructure involved a South Korean server 64.176.226[.]36 and the domain itemnania[.]com. The report indicated that this activity is consistent with North Korean-related attack characteristics, but the attribution confidence level is moderate, and the source of the AWS credentials remains unclear.

You may also like

In the name of charity, for the benefit of the family: How the Trump family turned charity into profit?

This set of "beautiful rhetoric and value return to one's own people" has not stopped at charitable foundations; it has now almost been transferred intact to American Bitcoin.

Will Gold Break $4,500 After Tonight's Fed Decision? What XAUT and PAXG Traders Need to Know

The Federal Reserve announces its June rate decision tonight. Could gold break $4,500 next? Explore the latest gold price prediction, key Fed scenarios, and what they mean for XAUT and PAXG traders.

Cursor, why did you get on Musk's spaceship?

SpaceX set a record with its IPO, spending a staggering $60 billion to acquire the popular AI programming unicorn Cursor just four days later. Musk is using the ultimate puzzle of "super computing power + top coding engine" to propel the market value skyrocketing, surpassing Amazon in one fell swoop...

Morning Report | DeepSeek completes over $7 billion in financing, with a valuation exceeding $50 billion; Musk's personal wealth has surpassed the total market value of Bitcoin

Overview of Important Market Events on June 16

SharpLink CEO: How to understand that Ethereum developers have just surpassed 1 million?

The most important question in the cryptocurrency industry is not which chain is the fastest, but rather where top builders choose to build in the long term. Ethereum has just surpassed one million cumulative developers; what does this number mean?

Morning Report | MiCA grace period expires on July 1; Kalshi's trading volume in the first week of the World Cup breaks $5.1 billion, setting a record

Overview of Important Market Events on June 15

Popular coins

Latest Crypto News

Read more
iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com