Key Takeaways North Korean hackers exploited a React front-end vulnerability (CVE-2025-55182) to breach crypto firms’ cloud infrastructure AWS credentials were […]Key Takeaways North Korean hackers exploited a React front-end vulnerability (CVE-2025-55182) to breach crypto firms’ cloud infrastructure AWS credentials were […]

North Korean Hackers Breached Crypto Cloud Systems Using Front-End Exploit, New Report Reveals

2026/03/10 01:38
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Key Takeaways

  • North Korean hackers exploited a React front-end vulnerability (CVE-2025-55182) to breach crypto firms’ cloud infrastructure
  • AWS credentials were stolen to extract private keys, source code, and sensitive configuration files
  • DPRK stole a record $2.02B in crypto in 2025 – roughly 13% of the country’s GDP
  • Tactics are shifting: fake recruiters and embedded IT workers are replacing purely technical attacks

Ctrl-Alt-Intel published its findings, attributing the operation to North Korean state-affiliated threat actors with “medium confidence.” The campaign zeroed in on exchange software vendors, staking platforms, and crypto exchanges – the operational backbone of the digital asset industry.

How the Attack Unfolded

The attackers’ initial foothold came through React2Shell (CVE-2025-55182), a critical front-end vulnerability that opened the door to cloud environments. From there, the group moved laterally using stolen AWS credentials, hunting for private keys, source code, and credentials buried in Secrets Manager, Terraform files, and Kubernetes configurations. Docker images tied to ChainUp clients were also pulled. The attack infrastructure traces back to a server in South Korea (IP: 64.176.226[.]36) and the domain itemnania[.]com.

The operation fits a broader, escalating pattern. North Korean hackers pulled in a record $2.02 billion in stolen cryptocurrency across 2025 – a 51% jump over 2024 – even as the total number of attacks dropped by 74%. The math tells the story: fewer hits, but far more precise and lucrative ones.

Those funds aren’t sitting idle. Analysts estimate stolen crypto now accounts for roughly 13% of North Korea’s GDP, with proceeds flowing directly into its nuclear and ballistic missile development programs.

READ MORE:

Trump-Linked Crypto Project WLFI Moves to Lock Out Small Investors

The Heists That Defined the Year

The scale of recent individual heists underscores how far the regime’s capabilities have advanced. The Lazarus Group – Pyongyang’s most prominent state-sponsored hacking unit – was behind the February 2025 theft of $1.5 billion from Bybit, the largest single crypto heist on record. The same group is suspected in a $30.4 million hit on Upbit later that year. DMM Bitcoin lost $308 million to a North Korea-attributed attack in December 2024.

What’s changing is the method. Cybersecurity analysts point to a deliberate pivot away from purely technical exploits toward social engineering. The “Contagious Interview” campaign has seen hackers impersonating recruiters to lure developers into executing malicious code under the guise of technical job assessments. Separately, North Korean operatives have been caught embedding themselves as IT workers inside crypto firms, gaining privileged internal access before pulling the plug.

What Comes Next

Dmitri Alperovitch, co-founder of CrowdStrike, has described DPRK-linked groups as more “creative and aggressive” than their Russian or Chinese counterparts – a characterization the Bybit heist did little to contradict.

Industry analysts aren’t expecting a slowdown. Despite measurable security improvements across decentralized finance, the consensus is that high-value, low-frequency attacks will continue through 2026. The incentive structure is simple: one successful breach can outperform dozens of smaller ones, and North Korea has demonstrated it knows how to find that breach.


The information provided in this article is for educational purposes only and does not constitute financial, investment, or trading advice. Coindoo.com does not endorse or recommend any specific investment strategy or cryptocurrency. Always conduct your own research and consult with a licensed financial advisor before making any investment decisions.

The post North Korean Hackers Breached Crypto Cloud Systems Using Front-End Exploit, New Report Reveals appeared first on Coindoo.

Market Opportunity
Cloud Logo
Cloud Price(CLOUD)
$0.03761
$0.03761$0.03761
-1.23%
USD
Cloud (CLOUD) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

VAT reductions seen viable with exemption crackdown

VAT reductions seen viable with exemption crackdown

THE GOVERNMENT will have to expand the tax base to make the proposed reductions in value-added tax (VAT) sustainable, and may need to resort to a crackdown on transactions
Share
Bworldonline2026/03/10 21:26
U.S. SEC chief Atkins said bond with sister agency CFTC to include joint meetings, exams

U.S. SEC chief Atkins said bond with sister agency CFTC to include joint meetings, exams

Policy Share Share this article
Copy linkX (Twitter)LinkedInFacebookEmail
U.S. SEC chief Atkins said bond with sister a
Share
Coindesk2026/03/11 01:30
Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be

Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be

The post Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be appeared on BitcoinEthereumNews.com. Jordan Love and the Green Bay Packers are off to a 2-0 start. Getty Images The Green Bay Packers are, once again, one of the NFL’s better teams. The Cleveland Browns are, once again, one of the league’s doormats. It’s why unbeaten Green Bay (2-0) is a 8-point favorite at winless Cleveland (0-2) Sunday according to betmgm.com. The money line is also Green Bay -500. Most expect this to be a Packers’ rout, and it very well could be. But Green Bay knows taking anyone in this league for granted can prove costly. “I think if you look at their roster, the paper, who they have on that team, what they can do, they got a lot of talent and things can turn around quickly for them,” Packers safety Xavier McKinney said. “We just got to kind of keep that in mind and know we not just walking into something and they just going to lay down. That’s not what they going to do.” The Browns certainly haven’t laid down on defense. Far from. Cleveland is allowing an NFL-best 191.5 yards per game. The Browns gave up 141 yards to Cincinnati in Week 1, including just seven in the second half, but still lost, 17-16. Cleveland has given up an NFL-best 45.5 rushing yards per game and just 2.1 rushing yards per attempt. “The biggest thing is our defensive line is much, much improved over last year and I think we’ve got back to our personality,” defensive coordinator Jim Schwartz said recently. “When we play our best, our D-line leads us there as our engine.” The Browns rank third in the league in passing defense, allowing just 146.0 yards per game. Cleveland has also gone 30 straight games without allowing a 300-yard passer, the longest active streak in the NFL.…
Share
BitcoinEthereumNews2025/09/18 00:41