DPRK Hackers Target Crypto Firms, Steal Keys and Cloud Assets in Coordinated Attacks
ID: 6b452101-ec11-5eb1-ad12-acd71a3f3063
STIX ID: report--6b452101-ec11-5eb1-ad12-acd71a3f3063
Feed Name: GBHackers
Suspected DPRK-linked operators exploited the critical React2Shell RCE (CVE-2025-55182) in Next.js/React Server Components to compromise crypto staking platforms, then used origin-unknown AWS access tokens and EKS access to enumerate S3/RDS/EC2, extract Terraform state, Kubernetes secrets, private container images and backend source code (including private wallet keys). The campaign used VShell and FRP-based C2 infrastructure, targeted staking platforms and exchange software vendors, and resulted in exfiltration of high-value artifacts; researchers provide IP/IPv6/domain IOCs and assess moderate confidence in DPRK attribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
