Suspected North Korea-Linked Hackers Hit Staking Platforms and Exchanges via Cloud Exploits, CtrlAltIntel Says
Security firm CtrlAltIntel reported that hackers suspected of links to North Korea targeted staking platforms, exchange software providers and cryptocurrency exchanges by exploiting React2Shell and compromised AWS credentials to access cloud resources and extract keys. The attackers exfiltrated five Docker images and source code including ChainUp client components, CtrlAltIntel said. The firm said the attackers operated infrastructure relying on a South Korea-based server at 64.176.226[.]36 and the domain itemnania[.]com, while attribution is assessed as moderate and the origin of the AWS credentials remains unclear.