[Subscribe Now] Track A-Level Transparency Project Biweekly Report and Discover the Top 1% of Projects
API Download the RootData App

Security Agency: Suspected North Korean hacker group collaborates to attack cryptocurrency companies to steal keys and cloud assets

3월 9, 2026 11:08:07

Share to

Security research organization Ctrl-Alt-Intel disclosed that a group of hackers suspected to be linked to North Korea has targeted staking platforms, exchange software vendors, and cryptocurrency exchanges.

The attackers exploited the React2Shell vulnerability (CVE-2025-55182) and compromised cloud environments using obtained AWS access credentials, enumerating resources such as S3, EC2, RDS, EKS, and ECR, and extracting keys and credentials from Secrets Manager, Terraform files, Kubernetes configurations, and Docker containers. Researchers stated that the attackers downloaded 5 Docker images and stole source code, including components related to ChainUp clients.

The attack infrastructure involved a South Korean server 64.176.226[.]36 and the domain itemnania[.]com. The report indicated that this activity is consistent with North Korean-related attack characteristics, but the attribution confidence level is moderate, and the source of the AWS credentials remains unclear.

Recent Fundraising

More
$24M 3月 14
$13M 3月 13

New Tokens

More
3月 11
3月 8
3月 4

Latest Updates on 𝕏

More
3月 14
3月 14
3月 13