Investigating Suspected DPRK-Linked Crypto Intrusions
2026-03-02 • Ctrl Alt Intel •
https://ctrlaltintel.com/threat%20research/DPRK-Crypto-Heist/
Ctrl-Alt-Intel observed suspected DPRK-linked intrusions against cryptocurrency organizations, including staking platforms, exchange software providers, and exchange cloud tenants. The activity combined React2Shell scanning and exploitation with separate use of valid AWS tokens to enumerate S3, RDS, EC2, IAM, EKS, ECR, Lambda, and Secrets Manager. Operators searched for Kubernetes configs, private keys, secrets, Terraform state, source code, Docker images, and database credentials, then pivoted from AWS IAM into Kubernetes through EKS kubeconfig updates. Reported infrastructure and tooling included VShell C2 on port 8082, FRP reverse proxy use on port 53, and South Korean VPN nodes for origin obfuscation. The findings matter because they show cloud-native post-exploitation focused on crypto supply-chain assets and proprietary systems that could enable theft, further compromise, or operational reuse.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 1c6770917d13fce1347f0cea9c9b86b0 | 2026-03-02 | 2026-03-02 |
| HASH | 8f633ade35df4f992eb28a2c5bc37cef | 2026-03-02 | 2026-03-02 |
| HASH | 42bd7c130c146246c88dc3462b0d21dd | 2026-03-02 | 2026-03-02 |
| DOMAIN | chainup.com | 2026-03-02 | 2026-03-02 |
| DOMAIN | git.uslab.dev | 2026-03-02 | 2026-03-02 |
| DOMAIN | itemnania.com | 2026-03-02 | 2026-03-02 |
| IPv4 | 64.176.226.36 | 2026-03-02 | 2026-03-02 |