Key Takeaways North Korean hackers exploited a React front-end vulnerability (CVE-2025-55182) to breach crypto firms’ cloud infrastructure AWS credentials were […]Key Takeaways North Korean hackers exploited a React front-end vulnerability (CVE-2025-55182) to breach crypto firms’ cloud infrastructure AWS credentials were […]

North Korean Hackers Breached Crypto Cloud Systems Using Front-End Exploit, New Report Reveals

2026/03/10 01:38
3 min read
For feedback or concerns regarding this content, please contact us at [email protected]

Key Takeaways

  • North Korean hackers exploited a React front-end vulnerability (CVE-2025-55182) to breach crypto firms’ cloud infrastructure
  • AWS credentials were stolen to extract private keys, source code, and sensitive configuration files
  • DPRK stole a record $2.02B in crypto in 2025 – roughly 13% of the country’s GDP
  • Tactics are shifting: fake recruiters and embedded IT workers are replacing purely technical attacks

Ctrl-Alt-Intel published its findings, attributing the operation to North Korean state-affiliated threat actors with “medium confidence.” The campaign zeroed in on exchange software vendors, staking platforms, and crypto exchanges – the operational backbone of the digital asset industry.

How the Attack Unfolded

The attackers’ initial foothold came through React2Shell (CVE-2025-55182), a critical front-end vulnerability that opened the door to cloud environments. From there, the group moved laterally using stolen AWS credentials, hunting for private keys, source code, and credentials buried in Secrets Manager, Terraform files, and Kubernetes configurations. Docker images tied to ChainUp clients were also pulled. The attack infrastructure traces back to a server in South Korea (IP: 64.176.226[.]36) and the domain itemnania[.]com.

The operation fits a broader, escalating pattern. North Korean hackers pulled in a record $2.02 billion in stolen cryptocurrency across 2025 – a 51% jump over 2024 – even as the total number of attacks dropped by 74%. The math tells the story: fewer hits, but far more precise and lucrative ones.

Those funds aren’t sitting idle. Analysts estimate stolen crypto now accounts for roughly 13% of North Korea’s GDP, with proceeds flowing directly into its nuclear and ballistic missile development programs.

READ MORE:

Trump-Linked Crypto Project WLFI Moves to Lock Out Small Investors

The Heists That Defined the Year

The scale of recent individual heists underscores how far the regime’s capabilities have advanced. The Lazarus Group – Pyongyang’s most prominent state-sponsored hacking unit – was behind the February 2025 theft of $1.5 billion from Bybit, the largest single crypto heist on record. The same group is suspected in a $30.4 million hit on Upbit later that year. DMM Bitcoin lost $308 million to a North Korea-attributed attack in December 2024.

What’s changing is the method. Cybersecurity analysts point to a deliberate pivot away from purely technical exploits toward social engineering. The “Contagious Interview” campaign has seen hackers impersonating recruiters to lure developers into executing malicious code under the guise of technical job assessments. Separately, North Korean operatives have been caught embedding themselves as IT workers inside crypto firms, gaining privileged internal access before pulling the plug.

What Comes Next

Dmitri Alperovitch, co-founder of CrowdStrike, has described DPRK-linked groups as more “creative and aggressive” than their Russian or Chinese counterparts – a characterization the Bybit heist did little to contradict.

Industry analysts aren’t expecting a slowdown. Despite measurable security improvements across decentralized finance, the consensus is that high-value, low-frequency attacks will continue through 2026. The incentive structure is simple: one successful breach can outperform dozens of smaller ones, and North Korea has demonstrated it knows how to find that breach.


The information provided in this article is for educational purposes only and does not constitute financial, investment, or trading advice. Coindoo.com does not endorse or recommend any specific investment strategy or cryptocurrency. Always conduct your own research and consult with a licensed financial advisor before making any investment decisions.

The post North Korean Hackers Breached Crypto Cloud Systems Using Front-End Exploit, New Report Reveals appeared first on Coindoo.

Market Opportunity
Cloud Logo
Cloud Price(CLOUD)
$0.0195
$0.0195$0.0195
+0.46%
USD
Cloud (CLOUD) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Michael Saylor’s Strategy Buys $2,010,000 Worth of Bitcoin in One of the Firm’s Largest Acquisitions Ever

Michael Saylor’s Strategy Buys $2,010,000 Worth of Bitcoin in One of the Firm’s Largest Acquisitions Ever

The post Michael Saylor’s Strategy Buys $2,010,000 Worth of Bitcoin in One of the Firm’s Largest Acquisitions Ever appeared on BitcoinEthereumNews.com. Michael
Share
BitcoinEthereumNews2026/05/19 15:17
One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight

One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight

The post One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight appeared on BitcoinEthereumNews.com. Frank Sinatra’s The World We Knew returns to the Jazz Albums and Traditional Jazz Albums charts, showing continued demand for his timeless music. Frank Sinatra performs on his TV special Frank Sinatra: A Man and his Music Bettmann Archive These days on the Billboard charts, Frank Sinatra’s music can always be found on the jazz-specific rankings. While the art he created when he was still working was pop at the time, and later classified as traditional pop, there is no such list for the latter format in America, and so his throwback projects and cuts appear on jazz lists instead. It’s on those charts where Sinatra rebounds this week, and one of his popular projects returns not to one, but two tallies at the same time, helping him increase the total amount of real estate he owns at the moment. Frank Sinatra’s The World We Knew Returns Sinatra’s The World We Knew is a top performer again, if only on the jazz lists. That set rebounds to No. 15 on the Traditional Jazz Albums chart and comes in at No. 20 on the all-encompassing Jazz Albums ranking after not appearing on either roster just last frame. The World We Knew’s All-Time Highs The World We Knew returns close to its all-time peak on both of those rosters. Sinatra’s classic has peaked at No. 11 on the Traditional Jazz Albums chart, just missing out on becoming another top 10 for the crooner. The set climbed all the way to No. 15 on the Jazz Albums tally and has now spent just under two months on the rosters. Frank Sinatra’s Album With Classic Hits Sinatra released The World We Knew in the summer of 1967. The title track, which on the album is actually known as “The World We Knew (Over and…
Share
BitcoinEthereumNews2025/09/18 00:02
Moody’s Assigns First-Ever Rating to Bitcoin-Backed Municipal Bond in Historic Crypto Finance Move

Moody’s Assigns First-Ever Rating to Bitcoin-Backed Municipal Bond in Historic Crypto Finance Move

TLDR: Moody’s assigned a provisional Ba2 rating to a $100M Bitcoin-backed New Hampshire municipal bond, a market first. The bond requires 160% Bitcoin overcollateralization
Share
Blockonomi2026/04/02 18:15

No Chart Skills? Still Profit

No Chart Skills? Still ProfitNo Chart Skills? Still Profit

Copy top traders in 3s with auto trading!