Investigating Suspected DPRK-Linked Crypto Intrusions

2026-03-02 Ctrl Alt Intel

https://ctrlaltintel.com/threat%20research/DPRK-Crypto-Heist/

Thumbnail for Investigating Suspected DPRK-Linked Crypto Intrusions

Ctrl-Alt-Intel observed suspected DPRK-linked intrusions against cryptocurrency organizations, including staking platforms, exchange software providers, and exchange cloud tenants. The activity combined React2Shell scanning and exploitation with separate use of valid AWS tokens to enumerate S3, RDS, EC2, IAM, EKS, ECR, Lambda, and Secrets Manager. Operators searched for Kubernetes configs, private keys, secrets, Terraform state, source code, Docker images, and database credentials, then pivoted from AWS IAM into Kubernetes through EKS kubeconfig updates. Reported infrastructure and tooling included VShell C2 on port 8082, FRP reverse proxy use on port 53, and South Korean VPN nodes for origin obfuscation. The findings matter because they show cloud-native post-exploitation focused on crypto supply-chain assets and proprietary systems that could enable theft, further compromise, or operational reuse.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 1c6770917d13fce1347f0cea9c9b86b0 2026-03-02 2026-03-02
HASH 8f633ade35df4f992eb28a2c5bc37cef 2026-03-02 2026-03-02
HASH 42bd7c130c146246c88dc3462b0d21dd 2026-03-02 2026-03-02
DOMAIN chainup.com 2026-03-02 2026-03-02
DOMAIN git.uslab.dev 2026-03-02 2026-03-02
DOMAIN itemnania.com 2026-03-02 2026-03-02
IPv4 64.176.226.36 2026-03-02 2026-03-02

Related Reports

« Back