Security firm Ctrl-Alt-Intel reports suspected North Korea-linked hackers targeted crypto platforms using React2Shell and AWS credentials. Security researchers Security firm Ctrl-Alt-Intel reports suspected North Korea-linked hackers targeted crypto platforms using React2Shell and AWS credentials. Security researchers

Security Firm Uncovers North Korea–Linked Attack on Crypto Infrastructure

2026/03/09 17:00
3 min read
For feedback or concerns regarding this content, please contact us at [email protected]

Security firm Ctrl-Alt-Intel reports suspected North Korea-linked hackers targeted crypto platforms using React2Shell and AWS credentials.

Security researchers have reported a cyber campaign targeting companies linked to crypto infrastructure.

The activity focused on staking platforms, exchange software providers, and crypto trading services.

Security firm Ctrl-Alt-Intel said the operation used cloud access and software vulnerabilities to obtain sensitive data from targeted systems.

Attack Targeted Crypto Infrastructure Providers

Security firm Ctrl-Alt-Intel said attackers focused on companies that support crypto services.

These included staking platforms, crypto exchanges, and firms that develop exchange software.

Researchers said the attackers attempted to access cloud environments and internal systems.

These systems often store operational data and software used by crypto trading platforms.

The campaign targeted technology providers connected to exchange infrastructure. Such firms often supply backend software used by multiple trading platforms.

Ctrl-Alt-Intel reported that attackers attempted to extract sensitive credentials and internal files. The activity aimed to obtain information that could help access production systems.

The firm stated that the attack affected infrastructure linked to several crypto platforms.

Investigators believe the operation aimed to gain deeper access into the crypto service supply chain.

Researchers said that infrastructure providers can become attractive targets because they manage systems used by multiple companies.

React2Shell and AWS Credentials Used in Intrusion

The investigation found that attackers exploited a vulnerability known as React2Shell. This flaw allowed them to interact with systems running vulnerable software components.

Through this method, attackers were able to gain access to cloud resources. Once inside, they searched for stored credentials and configuration data.

The report said that AWS credentials were also used during the intrusion. These credentials allowed attackers to interact with cloud services and internal environments.

Researchers believe the attackers attempted to obtain encryption keys and login credentials. Such information could provide access to protected infrastructure.

The attackers also extracted technical resources from targeted systems. According to the report, they exfiltrated five Docker images and source code from internal repositories.

Some of the extracted materials included components linked to ChainUp clients. ChainUp provides exchange infrastructure used by several crypto trading platforms.

The report stated that obtaining such files may help attackers study platform architecture and system design.

Related Reading: Suspected Infini Hacker Routes $32.7M in ETH Through Tornado Cash

Infrastructure and Attribution Details

The investigation identified technical infrastructure linked to the activity. Researchers traced some operations to a server located in South Korea.

The server used the address 64.176.226[.]36, according to the report. Investigators also identified the domain itemnania[.]com connected to the campaign.

Security analysts said the attack patterns showed similarities to previous operations linked to North Korea. These campaigns have often targeted financial platforms and digital asset services.

Ctrl-Alt-Intel said the attribution level remains moderate. The researchers explained that the origin of the AWS credentials used in the operation remains unclear.

Because of this uncertainty, investigators have not confirmed the full source of the intrusion. They said further monitoring is required to understand the campaign’s scope.

Security firms continue to monitor activity linked to crypto infrastructure attacks.

Researchers note that cloud access and software supply chains remain frequent targets for cyber groups operating in the digital asset sector.

The post Security Firm Uncovers North Korea–Linked Attack on Crypto Infrastructure appeared first on Live Bitcoin News.

Market Opportunity
CyberConnect Logo
CyberConnect Price(CYBER)
$0.5314
$0.5314$0.5314
-0.56%
USD
CyberConnect (CYBER) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Shibarium May No Longer Turbocharge Shiba Inu Price Rally, Here’s Reason

Shibarium May No Longer Turbocharge Shiba Inu Price Rally, Here’s Reason

The post Shibarium May No Longer Turbocharge Shiba Inu Price Rally, Here’s Reason appeared on BitcoinEthereumNews.com. Shibarium, the layer-2 blockchain of the Shiba Inu (SHIB) ecosystem, is battling to stay active. Shibarium has slipped from hitting transaction milestones to struggling to record any transactions on its platform, a development that could severely impact SHIB. Shibarium transactions crash from millions to near zero As per Shibariumscan data, the total daily transactions on Shibarium as of Sept. 16 stood at 11,600. This volume of transactions reflects how low the transaction count has dropped for the L2, whose daily average ranged between 3.5 million and 4 million last month. However, in the last week of August, daily transaction volume on Shibarium lost momentum, slipping from 1.3 million to 9,590 as of Aug. 28. This pattern has lingered for much of September, with the highest peak so far being on Sept. 5, when it posted 1.26 million transactions. The low user engagement has greatly affected the transaction count in recent days. In addition, the security breach over the weekend by malicious attackers on Shibarium has probably worsened issues. Although developer Kaal Dhairya reassured the community that the attack to steal millions of BONE tokens was successfully prevented, users’ confidence appears shaken. This has also impacted the price outlook for Shiba Inu, the ecosystem’s native token. Following reports of the malicious attack on Shibarium, SHIB dipped immediately into the red zone. Unlike on previous occasions where investors accumulated on the dip, market participants did not flock to Shiba Inu. Shiba Inu price struggles, can burn mechanism help? With the current near-zero crash in transaction volume for Shibarium, SHIB’s price cannot depend on it to support a rally. It might take a while to rebuild user confidence and for transactions to pick up again. In the meantime, Shiba Inu might have to rely on other means to boost prices from its low levels. This…
Share
BitcoinEthereumNews2025/09/18 07:57
Wormhole Unleashes W 2.0 Tokenomics for a Connected Blockchain Future

Wormhole Unleashes W 2.0 Tokenomics for a Connected Blockchain Future

TLDR Wormhole reinvents W Tokenomics with Reserve, yield, and unlock upgrades. W Tokenomics: 4% yield, bi-weekly unlocks, and a sustainable Reserve Wormhole shifts to long-term value with treasury, yield, and smoother unlocks. Stakers earn 4% base yield as Wormhole optimizes unlocks for stability. Wormhole’s new Tokenomics align growth, yield, and stability for W holders. Wormhole [...] The post Wormhole Unleashes W 2.0 Tokenomics for a Connected Blockchain Future appeared first on CoinCentral.
Share
Coincentral2025/09/18 02:07
Why Is Crypto Market Up Today? 5 Key Reasons Behind the Rally

Why Is Crypto Market Up Today? 5 Key Reasons Behind the Rally

The post Why Is Crypto Market Up Today? 5 Key Reasons Behind the Rally appeared on BitcoinEthereumNews.com. The crypto market is rallying today, with Bitcoin climbing
Share
BitcoinEthereumNews2026/03/11 04:47