logo

Suspected DPRK Threat Actors Compromise Crypto Firms, Steal Keys and Cloud Assets in Coordinated Attacks

ID: 898f74ab-4750-52e0-8e6b-dd44b150208a

STIX ID: report--898f74ab-4750-52e0-8e6b-dd44b150208a

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-03-05

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A coordinated campaign, likely linked to North Korean state-sponsored actors, targeted multiple tiers of the cryptocurrency supply chain—staking platforms, exchange software providers, and exchanges—using a mix of web-app exploitation (CVE-2025-55182) and pre-obtained AWS tokens to enumerate cloud infrastructure, extract private keys and source code, and exfiltrate Docker images and Terraform state files; attackers used Kubernetes pivots, tunneled C2 over DNS and IPv6, and left evidence in exposed open directories that revealed the full kill chain and tooling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.