Security firm Ctrl-Alt-Intel reports suspected North Korea-linked hackers targeted crypto platforms using React2Shell and AWS credentials. Security researchers Security firm Ctrl-Alt-Intel reports suspected North Korea-linked hackers targeted crypto platforms using React2Shell and AWS credentials. Security researchers

Security Firm Uncovers North Korea–Linked Attack on Crypto Infrastructure

2026/03/09 17:00
3 min di lettura
Per feedback o dubbi su questo contenuto, contattateci all'indirizzo [email protected].

Security firm Ctrl-Alt-Intel reports suspected North Korea-linked hackers targeted crypto platforms using React2Shell and AWS credentials.

Security researchers have reported a cyber campaign targeting companies linked to crypto infrastructure.

The activity focused on staking platforms, exchange software providers, and crypto trading services.

Security firm Ctrl-Alt-Intel said the operation used cloud access and software vulnerabilities to obtain sensitive data from targeted systems.

Attack Targeted Crypto Infrastructure Providers

Security firm Ctrl-Alt-Intel said attackers focused on companies that support crypto services.

These included staking platforms, crypto exchanges, and firms that develop exchange software.

Researchers said the attackers attempted to access cloud environments and internal systems.

These systems often store operational data and software used by crypto trading platforms.

The campaign targeted technology providers connected to exchange infrastructure. Such firms often supply backend software used by multiple trading platforms.

Ctrl-Alt-Intel reported that attackers attempted to extract sensitive credentials and internal files. The activity aimed to obtain information that could help access production systems.

The firm stated that the attack affected infrastructure linked to several crypto platforms.

Investigators believe the operation aimed to gain deeper access into the crypto service supply chain.

Researchers said that infrastructure providers can become attractive targets because they manage systems used by multiple companies.

React2Shell and AWS Credentials Used in Intrusion

The investigation found that attackers exploited a vulnerability known as React2Shell. This flaw allowed them to interact with systems running vulnerable software components.

Through this method, attackers were able to gain access to cloud resources. Once inside, they searched for stored credentials and configuration data.

The report said that AWS credentials were also used during the intrusion. These credentials allowed attackers to interact with cloud services and internal environments.

Researchers believe the attackers attempted to obtain encryption keys and login credentials. Such information could provide access to protected infrastructure.

The attackers also extracted technical resources from targeted systems. According to the report, they exfiltrated five Docker images and source code from internal repositories.

Some of the extracted materials included components linked to ChainUp clients. ChainUp provides exchange infrastructure used by several crypto trading platforms.

The report stated that obtaining such files may help attackers study platform architecture and system design.

Related Reading: Suspected Infini Hacker Routes $32.7M in ETH Through Tornado Cash

Infrastructure and Attribution Details

The investigation identified technical infrastructure linked to the activity. Researchers traced some operations to a server located in South Korea.

The server used the address 64.176.226[.]36, according to the report. Investigators also identified the domain itemnania[.]com connected to the campaign.

Security analysts said the attack patterns showed similarities to previous operations linked to North Korea. These campaigns have often targeted financial platforms and digital asset services.

Ctrl-Alt-Intel said the attribution level remains moderate. The researchers explained that the origin of the AWS credentials used in the operation remains unclear.

Because of this uncertainty, investigators have not confirmed the full source of the intrusion. They said further monitoring is required to understand the campaign’s scope.

Security firms continue to monitor activity linked to crypto infrastructure attacks.

Researchers note that cloud access and software supply chains remain frequent targets for cyber groups operating in the digital asset sector.

The post Security Firm Uncovers North Korea–Linked Attack on Crypto Infrastructure appeared first on Live Bitcoin News.

Opportunità di mercato
Logo CyberConnect
Valore CyberConnect (CYBER)
$0.5267
$0.5267$0.5267
-1.18%
USD
Grafico dei prezzi in tempo reale di CyberConnect (CYBER)
Disclaimer: gli articoli ripubblicati su questo sito provengono da piattaforme pubbliche e sono forniti esclusivamente a scopo informativo. Non riflettono necessariamente le opinioni di MEXC. Tutti i diritti rimangono agli autori originali. Se ritieni che un contenuto violi i diritti di terze parti, contatta [email protected] per la rimozione. MEXC non fornisce alcuna garanzia in merito all'accuratezza, completezza o tempestività del contenuto e non è responsabile per eventuali azioni intraprese sulla base delle informazioni fornite. Il contenuto non costituisce consulenza finanziaria, legale o professionale di altro tipo, né deve essere considerato una raccomandazione o un'approvazione da parte di MEXC.

Potrebbe anche piacerti

U.S. Treasury Recognizes Legitimate Uses for Crypto Mixers, Proposes “Hold Law” for Suspicious Assets

U.S. Treasury Recognizes Legitimate Uses for Crypto Mixers, Proposes “Hold Law” for Suspicious Assets

Bitcoin Magazine U.S. Treasury Recognizes Legitimate Uses for Crypto Mixers, Proposes “Hold Law” for Suspicious Assets The U.S. Treasury Department told Congress
Condividi
bitcoinmagazine2026/03/09 22:29
Best Altcoins to Buy After Google Acquires Stake in Bitcoin Mining Company

Best Altcoins to Buy After Google Acquires Stake in Bitcoin Mining Company

The post Best Altcoins to Buy After Google Acquires Stake in Bitcoin Mining Company appeared on BitcoinEthereumNews.com. Best Altcoins to Buy After Google Acquires Stake in Bitcoin Mining Company Sign Up for Our Newsletter! For updates and exclusive offers enter your email. As a crypto writer, Krishi splits his time between decoding the chaos of the markets and writing about it in a way that doesn’t put you to sleep. He’s been at it for nearly two years in the crypto trenches. Yes, he regrets missing the magnificent rallies that came before that (who doesn’t!), but he’s more than ready to put his money where his words are. Before diving headfirst into crypto, Krishi spent over five years writing for some of the biggest names in tech, including TechRadar, Tom’s Guide, and PC Gaming, covering everything from gadgets and cybersecurity to gaming and software. When he’s not scouring and writing about the latest happenings in crypto, Krishi trades the forex market while keeping crypto in his long-term HODL plans. He’s a Bitcoin believer, though he never lets that bias creep into his writing. This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Center or Cookie Policy. I Agree Source: https://bitcoinist.com/best-altcoins-to-buy-as-google-acquires-stake-in-bitcoin-mining-company/
Condividi
BitcoinEthereumNews2025/09/26 22:51
Strategy returns to strong weekly buying with 17,994 BTC

Strategy returns to strong weekly buying with 17,994 BTC

The post Strategy returns to strong weekly buying with 17,994 BTC appeared on BitcoinEthereumNews.com. Strategy performed its biggest weekly purchase since January
Condividi
BitcoinEthereumNews2026/03/09 21:47