logo

DPRK Hackers Target Crypto Firms, Steal Keys and Cloud Assets in Coordinated Attacks

ID: 6b452101-ec11-5eb1-ad12-acd71a3f3063

STIX ID: report--6b452101-ec11-5eb1-ad12-acd71a3f3063

Feed Name: GBHackers

Threat Score
86/100

Date Published: 2026-03-05

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Suspected DPRK-linked operators exploited the critical React2Shell RCE (CVE-2025-55182) in Next.js/React Server Components to compromise crypto staking platforms, then used origin-unknown AWS access tokens and EKS access to enumerate S3/RDS/EC2, extract Terraform state, Kubernetes secrets, private container images and backend source code (including private wallet keys). The campaign used VShell and FRP-based C2 infrastructure, targeted staking platforms and exchange software vendors, and resulted in exfiltration of high-value artifacts; researchers provide IP/IPv6/domain IOCs and assess moderate confidence in DPRK attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.