A sophisticated cyber campaign targeting cryptocurrency companies has been uncovered by cybersecurity firm Ctrl-Alt-Intel, with researchers suggesting that the attacks may be linked to threat actors associated with North Korea.
The operation reportedly targeted multiple entities across the crypto ecosystem, including staking platforms, exchange software providers, and cryptocurrency exchanges.
According to the firm’s investigation, the threat actor systematically compromised organizations by exploiting web application vulnerabilities and gaining unauthorized access to cloud infrastructure.
In several cases, the attackers used valid credentials to infiltrate Amazon Web Services environments operated by targeted companies.
One of the key techniques identified in the campaign involved the exploitation of a vulnerability known as React2Shell.
By leveraging this flaw alongside exposed AWS credentials, attackers were able to access cloud resources, extract cryptographic keys, and collect sensitive credentials belonging to crypto companies.
Researchers reported that the attackers successfully exfiltrated proprietary software and development resources, including five Docker images and portions of exchange source code.
Among the materials stolen were components linked to clients of ChainUp, a major provider of exchange infrastructure used by numerous digital asset platforms.
The attackers’ infrastructure also provided clues about their operations. Investigators discovered activity linked to a server located in South Korea using the IP address 64.176.226[.]36, along with a domain associated with the campaign, itemnania[dot]com.
These resources were allegedly used to stage and distribute malicious payloads during the intrusion process.
Despite the strong indicators uncovered during the investigation, researchers noted that attribution remains moderate rather than definitive.
While the targeting patterns and operational behavior resemble tactics commonly associated with North Korean cyber groups, the exact origin of the compromised AWS credentials remains unclear.
The findings highlight growing concerns about supply-chain vulnerabilities within the cryptocurrency sector.
By infiltrating software providers and infrastructure services, attackers can potentially gain access to multiple downstream companies, amplifying the scale and impact of such cyber operations across the digital asset industry.
