North Korean hackers exploited shared cloud service to rob crypto firms

2023-7-21 23:20

North Korean state hackers exploited a cloud services provider called JumpCloud to steal funds from crypto companies that use its services, Reuters reported on July 20.

Reuter’s confidential sources indicate that the North Korean state-backed hackers had a specific focus on cryptocurrency companies. However, the report did not disclose the names of the impacted companies or the exact quantity of cryptocurrency purportedly stolen.

Crowdstrike, a cybersecurity firm collaborating with JumpCloud to probe the incident, attributed the attack to a group known as Labyrinth Chollima. Although the representative from Crowdstrike did not confirm if any cryptocurrency was stolen, he noted the group’s history of targeting cryptocurrency companies.

In an update on July 20, JumpCloud announced North Korea as the perpetrator of the attack, It also disclosed that less than five of the company’s 200,000 corporate clients, and less than 10 devices, were affected.

Previously, the company described a spear-phishing campaign conducted by a “sophisticated nation-state sponsored threat actor.” The company said that the attack began on June 22 and said that it detected those activities on June 27.

JumpCloud said that it did not find any indication that customers were affected at that time. The company nevertheless updated credentials and took extra steps to preserve security; it also contacted law enforcement. However, on July 5, the company discovered additional activity that affected its customers, who were then informed of the situation.

JumpCloud says attackers are advanced

JumpCloud called the attackers “sophisticated and persistent adversaries with advanced capabilities” and said the best defense involves sharing information.

JumpCloud said that the attack vector involved data injection into its commands framework. The attack was found to be highly targeted and specific to certain customers. The attack produced a list of IOCs (Indicators of Compromise), which JumpCloud has shared.

North Korean attackers have been involved in other crypto attacks including those against Axie Infinity and Horizon Bridge. Estimates from Chainalysis suggest that North Korean groups stole $1.7 billion amidst $3.8 billion in broader crypto thefts in 2022.

The post North Korean hackers exploited shared cloud service to rob crypto firms appeared first on CryptoSlate.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

North Korean Won (KPW) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 0.00 %
Cегодня L: $0 - H: $0
Капитализация $0 Rank 99999
Доступно / Всего 0 KPW

hackers korean north services crypto companies cloud

hackers korean → Результатов: 126


The international sting operation aimed at apprehending North Korean cryptocurrency hackers is detailed within.

A joint team of South Korean spies and American private investigators gathered at the South Korean intelligence service to track $100 million stolen from California cryptocurrency firm, Harmony. The team had been waiting for North Korean hackers to move the stolen crypto into accounts that could be converted to dollars or Chinese yuan, hard currency […] Сообщение The international sting operation aimed at apprehending North Korean cryptocurrency hackers is detailed within. появились сначала на Coinstelegram.

2023-4-10 12:48


North Korean Hackers Pose As VC Firms And Banks To Steal Millions From Crypto Startups

North Korean hackers are taking it a notch higher by pretending to be venture capitalists to steal from cryptocurrency startups. BlueNoroff, the name given by cybersecurity experts to a crew associated with the North Korean government-funded hacking operation Lazarus Group, has expanded its target list to include venture capital firms, cryptocurrency startups, and banks, a report by cybersecurity […]

2022-12-29 13:39


Hackers Mess With South Korea’s YouTube Channel To Play Elon Musk Crypto Video

According to local media sources, the official South Korean government YouTube channel was hacked on Saturday to show a video of SpaceX CEO Elon Musk discussing cryptocurrencies. Yonhap News reports that once the hackers gained access to this channel’s controls, they renamed it “SpaceX Invest” to make it appear to be affiliated with Musk’s aerospace […]

2022-9-5 17:50


North Korea Retains Lead In Crypto Crimes, Over $1.5 B Stolen

Indeed, the crypto-space has become the favorite place for cybercriminals worldwide for some years, but some countries are more prolific than others. Similarly, continuous cyber-attacks on crypto-oriented businesses by North Korean hackers have set it at the top of the list of five leading countries in crypto crimes 2022, per the report of Coincub published […]

2022-6-30 23:00