North Korea-linked hackers exploited React2Shell and AWS credentials to breach staking platforms, exchanges, and software providers, stealing Docker images and source code including ChainUp components.
Security & Exploits ·
Security firm Ctrl-Alt-Intel reported that hackers suspected of North Korea ties targeted staking platforms, exchange software providers, and crypto exchanges through exploitation of React2Shell and AWS credentials to gain access to cloud resources. The attackers extracted keys, credentials, and exfiltrated 5 Docker images and source code containing ChainUp client components.
The breach leveraged compromised AWS credentials whose origin remains unclear, according to the report. Infrastructure associated with the campaign used a South Korea-based server at 64.176.226[.]36 and the domain itemnania[.]com, suggesting operational staging points for the intrusions.
Attribution to North Korea remains assessed at moderate confidence. The specific identity of affected staking platforms and exchanges has not been disclosed, and the full scope of credential exposure and whether the Docker images or source code have been weaponized or sold remains unknown.