Investigating Suspected DPRK-Linked Crypto Intrusions
ID: 5000cc38-096c-5de3-857a-604da5baab97
STIX ID: report--5000cc38-096c-5de3-857a-604da5baab97
Feed Name: Ctrl-Alt-Int3l
This report details a focused campaign against multiple tiers of the cryptocurrency supply chain in which a threat actor mass-scanned and exploited React2Shell vulnerabilities and used pre-obtained AWS credentials to enumerate S3, ECR, EKS, RDS, Lambda and Secrets Manager, pivot into Kubernetes, and exfiltrate proprietary exchange source code, Docker images, and secrets. The authors provide MITRE ATT&CK mappings, IOCs (IPv4/IPv6/domain), command examples observed in logs and histories, and assess with moderate confidence a possible DPRK affiliation based on tradecraft, targeting, and infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
