The post Ctrl-Alt-Intel Uncovers Cyberattack Targeting Crypto Firms appeared on BitcoinEthereumNews.com. Attackers exploited the React2Shell vulnerability and stoleThe post Ctrl-Alt-Intel Uncovers Cyberattack Targeting Crypto Firms appeared on BitcoinEthereumNews.com. Attackers exploited the React2Shell vulnerability and stole

Ctrl-Alt-Intel Uncovers Cyberattack Targeting Crypto Firms

For feedback or concerns regarding this content, please contact us at [email protected]
  • Attackers exploited the React2Shell vulnerability and stole AWS credentials to access systems.
  • Hackers searched cloud infrastructure for private keys, credentials, and exchange source code.
  • Evidence and tactics point toward North Korean cyber groups targeting the crypto industry.

A sophisticated hacking campaign targeting the heart of the cryptocurrency industry has been exposed by cybersecurity firm Ctrl-Alt-Intel, and the fingerprints left behind suggest possible links to North Korean threat actors.

The Break-In

The attackers used multiple entry points. In some cases, they exploited React2Shell, a vulnerability in a popular web framework, scanning the internet for crypto platforms running outdated software. 

In another instance, the attackers appeared to already possess valid Amazon Web Services credentials, allowing them to enter a crypto exchange’s cloud environment without triggering typical intrusion methods. How those credentials were obtained remains unknown.

The Methodical Pillage

What followed was not a smash-and-grab. It was a careful, room-by-room search of an entire digital infrastructure. The attackers combed through cloud storage buckets hunting for private keys and configuration files. 

They traced through infrastructure blueprints looking for database passwords. They tested network connections, and when one database proved unreachable, they simply reconfigured it to be publicly accessible and connected anyway.

Then came the real prize. Five proprietary Docker container images, essentially the packaged source code of a live cryptocurrency exchange, were pulled and taken. Private repositories were cloned. 

Application secrets and hardcoded credentials were harvested from cloud vaults, Kubernetes clusters, and live containers. One staking platform had its entire backend stripped, including a private wallet key. A small amount of cryptocurrency was transferred from the associated address shortly after.

The Trail Back to Pyongyang

Researchers were careful with their language, stopping short of a definitive accusation. But the evidence they assembled, the systematic targeting of crypto businesses, the tools used, the infrastructure patterns, and the nature of what was stolen align closely with North Korean threat actors who have spent years raiding the crypto industry to generate hard currency for a sanctions-choked regime.

To obscure their tracks, the attackers routed their activity through South Korean VPN nodes, a layer of misdirection designed to complicate exactly the kind of investigation that ultimately caught them.

Ctrl-Alt-Intel has notified affected companies. The rest of the industry has been put on notice.

Related: Crypto Activity by Sanctioned States Expands Across Global Networks

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.

Source: https://coinedition.com/ctrl-alt-intel-uncovers-sophisticated-cyberattack-targeting-crypto-firms/

Market Opportunity
Cloud Logo
Cloud Price(CLOUD)
$0.03893
$0.03893$0.03893
+1.56%
USD
Cloud (CLOUD) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Tags:

You May Also Like

Taiko and Chainlink to Unleash Reliable Onchain Data for DeFi Ecosystem

Taiko and Chainlink to Unleash Reliable Onchain Data for DeFi Ecosystem

Taiko and Chainlink Data Streams to deliver secure, high-speed onchain data by empowering next-generation DeFi protocols and institutional-grade adoption.
Share
Blockchainreporter2025/09/18 06:10
Russia’s Central Bank Prepares Crackdown on Crypto in New 2026–2028 Strategy

Russia’s Central Bank Prepares Crackdown on Crypto in New 2026–2028 Strategy

The Central Bank of Russia’s long-term strategy for 2026 to 2028 paints a picture of growing concern. The document, prepared […] The post Russia’s Central Bank Prepares Crackdown on Crypto in New 2026–2028 Strategy appeared first on Coindoo.
Share
Coindoo2025/09/18 02:30
DOGE ETF Hype Fades as Whales Sell and Traders Await Decline

DOGE ETF Hype Fades as Whales Sell and Traders Await Decline

The post DOGE ETF Hype Fades as Whales Sell and Traders Await Decline appeared on BitcoinEthereumNews.com. Leading meme coin Dogecoin (DOGE) has struggled to gain momentum despite excitement surrounding the anticipated launch of a US-listed Dogecoin ETF this week. On-chain data reveals a decline in whale participation and a general uptick in coin selloffs across exchanges, hinting at the possibility of a deeper price pullback in the coming days. Sponsored Sponsored DOGE Faces Decline as Whales Hold Back, Traders Sell The market is anticipating the launch of Rex-Osprey’s Dogecoin ETF (DOJE) tomorrow, which is expected to give traditional investors direct exposure to Dogecoin’s price movements.  However, DOGE’s price performance has remained muted ahead of the milestone, signaling a lack of enthusiasm from traders. According to on-chain analytics platform Nansen, whale accumulation has slowed notably over the past week. Large investors, with wallets containing DOGE coins worth more than $1 million, appear unconvinced by the ETF narrative and have reduced their holdings by over 4% in the past week.  For token TA and market updates: Want more token insights like this? Sign up for Editor Harsh Notariya’s Daily Crypto Newsletter here. Dogecoin Whale Activity. Source: Nansen When large holders reduce their accumulation, it signals a bearish shift in market sentiment. This reduced DOGE demand from significant players can lead to decreased buying pressure, potentially resulting in price stagnation or declines in the near term. Sponsored Sponsored Furthermore, DOGE’s exchange reserve has risen steadily in the past week, suggesting that more traders are transferring DOGE to exchanges with the intent to sell. As of this writing, the altcoin’s exchange balance sits at 28 billion DOGE, climbing by 12% in the past seven days. DOGE Balance on Exchanges. Source: Glassnode A rising exchange balance indicates that holders are moving their assets to trading platforms to sell rather than to hold. This influx of coins onto exchanges increases the available supply in…
Share
BitcoinEthereumNews2025/09/18 05:07