DPRK Hackers Target Crypto Firms, Steal Keys and Cloud Assets in Coordinated Attacks
Suspected DPRK-linked threat actors have been observed compromising cryptocurrency firms through a coordinated campaign that blends web-app exploitation, cloud abuse, and secrets theft to position for large‑scale digital asset theft.
The intrusions show a full kill chain from initial access via the React2Shell vulnerability (CVE‑2025‑55182) to deep AWS and Kubernetes reconnaissance and exfiltration of proprietary exchange software and keys.
Attackers first scan for internet‑facing crypto staking platforms vulnerable to React2Shell, a critical unauthenticated remote code execution flaw in React Server Components and Next.js with a maximum CVSS 10.0 rating.
Using mass‑scan tooling and WAF‑bypass options, they identify exposed endpoints and exploit them to run arbitrary commands on server‑side application components.
From one compromised “USDT staking” platform, investigators recovered archived backend Next.js source code, including an environment file that exposed Tron wallet addresses and private keys, as well as a Python web3 script reusing that same key for balance checks.
Blockchain telemetry around the time of active React2Shell exploitation suggests at least one suspicious TRX transfer, though attribution of that specific theft remains unclear.
According to the report, threat actor has systematically compromised cryptocurrency organisations: exploiting web application vulnerabilities, pillaging AWS tenants with valid credentials.
In parallel to web exploitation, the same cluster of operators used valid but origin‑unknown AWS access tokens to compromise a separate crypto exchange tenant.
We recovered files indicating that the threat actor had successfully archived and exfiltrated source code from a victim organisation. From TOS of the exfiltrated source code, we can see this is a “USDT staking” product.
The threat actors had compromised and exfiltrated the backend source code of a crypto “staking” platform. Additionally, we could see artefacts within the source code that indicated this web-server had already been exploited by unrelated actors.
Ctrl-Alt-Intel has previously blogged about React2Shell exploitation in the wild, and within the source code we saw similar malware delivered.
After importing credentials, they validated identity with STS, then immediately enumerated S3 buckets and RDS instances to map available data stores and services.
The threat actors systematically enumerated core AWS services used by modern exchanges: EC2, RDS, S3, Lambda, EKS, ECR, and IAM.
They recursively listed S3 paths while grepping for kubeconfig directories, key material, configuration files, and Terraform state files high‑value artifacts that often contain passwords, API keys, IPs, and database identifiers.
Terraform state files were streamed directly from S3 and filtered for terms such as “password”, “db_name”, “aws_db_instance”, and “public_ip”, providing a blueprint of the victim’s infrastructure and credentials.
With sufficient IAM permissions, the actors pivoted from AWS to Kubernetes by using aws eks update-kubeconfig to configure kubectl access to managed EKS clusters.
Once authenticated, they listed pods across all namespaces and focused on nodes and workloads related to cryptocurrency operations.
Using IAM‑backed ECR authentication, they enumerated private container registries, identified sensitive images, and pulled them to attacker‑controlled infrastructure.
At least five Docker images containing proprietary exchange logic, hardcoded credentials, and internal routing details were exported to portable tar archives for exfiltration.
The actors then queried AWS Secrets Manager, Kubernetes ConfigMaps and Secrets, and configuration files inside running containers to extract plaintext secrets, before cloning private Git repositories for full backend visibility.
For command and control, the campaign used a licensed VShell server on port 8082 alongside FRP (Fast Reverse Proxy) running on port 53, a pattern consistent with DPRK operations that use FRP for covert tunneling and resilient C2.
Core attack infrastructure was hosted on a VPS in South Korea linked to the domain itemnania[.]com, with both IPv4 and IPv6 in use, and analysts observed SSH activity and tunneling via South Korean VPN exit nodes for additional origin obfuscation.
Victimology and tradecraft indicate a focused crypto supply‑chain campaign: staking platforms, exchange software vendors, and exchanges themselves were all targeted, with emphasis on backend source code, database credentials, private keys, and exchange middleware rather than immediate mass theft of funds.
Combined with DPRK’s documented history of exploiting React2Shell, abusing AWS tokens in crypto heists, and reusing FRP infrastructure, researchers assess with moderate confidence that this activity aligns with DPRK‑affiliated actors, though no single indicator is conclusive, and some tools, such as VShell, are also used by other nations.
| Type | Value | Context |
|---|---|---|
| IPv4 | 64.176.226[.]36 | Primary VPS |
| IPv6 | 2401:c080:1c01:c6:5400:5ff:fec1[:]ccc9 | VPS IPv6 |
| Domain | itemnania[.]com | Associated with primary server; registered in South Korea |
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…