Security firm Ctrl-Alt-Intel reports suspected North Korea-linked hackers targeted crypto platforms using React2Shell and AWS credentials. Security researchers Security firm Ctrl-Alt-Intel reports suspected North Korea-linked hackers targeted crypto platforms using React2Shell and AWS credentials. Security researchers

Security Firm Uncovers North Korea–Linked Attack on Crypto Infrastructure

2026/03/09 17:00
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Security firm Ctrl-Alt-Intel reports suspected North Korea-linked hackers targeted crypto platforms using React2Shell and AWS credentials.

Security researchers have reported a cyber campaign targeting companies linked to crypto infrastructure.

The activity focused on staking platforms, exchange software providers, and crypto trading services.

Security firm Ctrl-Alt-Intel said the operation used cloud access and software vulnerabilities to obtain sensitive data from targeted systems.

Attack Targeted Crypto Infrastructure Providers

Security firm Ctrl-Alt-Intel said attackers focused on companies that support crypto services.

These included staking platforms, crypto exchanges, and firms that develop exchange software.

Researchers said the attackers attempted to access cloud environments and internal systems.

These systems often store operational data and software used by crypto trading platforms.

The campaign targeted technology providers connected to exchange infrastructure. Such firms often supply backend software used by multiple trading platforms.

Ctrl-Alt-Intel reported that attackers attempted to extract sensitive credentials and internal files. The activity aimed to obtain information that could help access production systems.

The firm stated that the attack affected infrastructure linked to several crypto platforms.

Investigators believe the operation aimed to gain deeper access into the crypto service supply chain.

Researchers said that infrastructure providers can become attractive targets because they manage systems used by multiple companies.

React2Shell and AWS Credentials Used in Intrusion

The investigation found that attackers exploited a vulnerability known as React2Shell. This flaw allowed them to interact with systems running vulnerable software components.

Through this method, attackers were able to gain access to cloud resources. Once inside, they searched for stored credentials and configuration data.

The report said that AWS credentials were also used during the intrusion. These credentials allowed attackers to interact with cloud services and internal environments.

Researchers believe the attackers attempted to obtain encryption keys and login credentials. Such information could provide access to protected infrastructure.

The attackers also extracted technical resources from targeted systems. According to the report, they exfiltrated five Docker images and source code from internal repositories.

Some of the extracted materials included components linked to ChainUp clients. ChainUp provides exchange infrastructure used by several crypto trading platforms.

The report stated that obtaining such files may help attackers study platform architecture and system design.

Related Reading: Suspected Infini Hacker Routes $32.7M in ETH Through Tornado Cash

Infrastructure and Attribution Details

The investigation identified technical infrastructure linked to the activity. Researchers traced some operations to a server located in South Korea.

The server used the address 64.176.226[.]36, according to the report. Investigators also identified the domain itemnania[.]com connected to the campaign.

Security analysts said the attack patterns showed similarities to previous operations linked to North Korea. These campaigns have often targeted financial platforms and digital asset services.

Ctrl-Alt-Intel said the attribution level remains moderate. The researchers explained that the origin of the AWS credentials used in the operation remains unclear.

Because of this uncertainty, investigators have not confirmed the full source of the intrusion. They said further monitoring is required to understand the campaign’s scope.

Security firms continue to monitor activity linked to crypto infrastructure attacks.

Researchers note that cloud access and software supply chains remain frequent targets for cyber groups operating in the digital asset sector.

The post Security Firm Uncovers North Korea–Linked Attack on Crypto Infrastructure appeared first on Live Bitcoin News.

Market Opportunity
CyberConnect Logo
CyberConnect Price(CYBER)
$0.533
$0.533$0.533
-0.26%
USD
CyberConnect (CYBER) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Fed Decides On Interest Rates Today—Here’s What To Watch For

Fed Decides On Interest Rates Today—Here’s What To Watch For

The post Fed Decides On Interest Rates Today—Here’s What To Watch For appeared on BitcoinEthereumNews.com. Topline The Federal Reserve on Wednesday will conclude a two-day policymaking meeting and release a decision on whether to lower interest rates—following months of pressure and criticism from President Donald Trump—and potentially signal whether additional cuts are on the way. President Donald Trump has urged the central bank to “CUT INTEREST RATES, NOW, AND BIGGER” than they might plan to. Getty Images Key Facts The central bank is poised to cut interest rates by at least a quarter-point, down from the 4.25% to 4.5% range where they have been held since December to between 4% and 4.25%, as Wall Street has placed 100% odds of a rate cut, according to CME’s FedWatch, with higher odds (94%) on a quarter-point cut than a half-point (6%) reduction. Fed governors Christopher Waller and Michelle Bowman, both Trump appointees, voted in July for a quarter-point reduction to rates, and they may dissent again in favor of a large cut alongside Stephen Miran, Trump’s Council of Economic Advisers’ chair, who was sworn in at the meeting’s start on Tuesday. It’s unclear whether other policymakers, including Kansas City Fed President Jeffrey Schmid and St. Louis Fed President Alberto Musalem, will favor larger cuts or opt for no reduction. Fed Chair Jerome Powell said in his Jackson Hole, Wyoming, address last month the central bank would likely consider a looser monetary policy, noting the “shifting balance of risks” on the U.S. economy “may warrant adjusting our policy stance.” David Mericle, an economist for Goldman Sachs, wrote in a note the “key question” for the Fed’s meeting is whether policymakers signal “this is likely the first in a series of consecutive cuts” as the central bank is anticipated to “acknowledge the softening in the labor market,” though they may not “nod to an October cut.” Mericle said he…
Share
BitcoinEthereumNews2025/09/18 00:23
BetFury is at SBC Summit Lisbon 2025: Affiliate Growth in Focus

BetFury is at SBC Summit Lisbon 2025: Affiliate Growth in Focus

The post BetFury is at SBC Summit Lisbon 2025: Affiliate Growth in Focus appeared on BitcoinEthereumNews.com. Press Releases are sponsored content and not a part of Finbold’s editorial content. For a full disclaimer, please . Crypto assets/products can be highly risky. Never invest unless you’re prepared to lose all the money you invest. Curacao, Curacao, September 17th, 2025, Chainwire BetFury steps onto the stage of SBC Summit Lisbon 2025 — one of the key gatherings in the iGaming calendar. From 16 to 18 September, the platform showcases its brand strength, deepens affiliate connections, and outlines its plans for global expansion. BetFury continues to play a role in the evolving crypto and iGaming partnership landscape. BetFury’s Participation at SBC Summit The SBC Summit gathers over 25,000 delegates, including 6,000+ affiliates — the largest concentration of affiliate professionals in iGaming. For BetFury, this isn’t just visibility, it’s a strategic chance to present its Affiliate Program to the right audience. Face-to-face meetings, dedicated networking zones, and affiliate-focused sessions make Lisbon the ideal ground to build new partnerships and strengthen existing ones. BetFury Meets Affiliate Leaders at its Massive Stand BetFury arrives at the summit with a massive stand placed right in the center of the Affiliate zone. Designed as a true meeting hub, the stand combines large LED screens, a sleek interior, and the best coffee at the event — but its core mission goes far beyond style. Here, BetFury’s team welcomes partners and affiliates to discuss tailored collaborations, explore growth opportunities across multiple GEOs, and expand its global Affiliate Program. To make the experience even more engaging, the stand also hosts: Affiliate Lottery — a branded drum filled with exclusive offers and personalized deals for affiliates. Merch Kits — premium giveaways to boost brand recognition and leave visitors with a lasting conference memory. Besides, at SBC Summit Lisbon, attendees have a chance to meet the BetFury team along…
Share
BitcoinEthereumNews2025/09/18 01:20
Is Bitcoin Treasury Hype Fading? Data Suggests So

Is Bitcoin Treasury Hype Fading? Data Suggests So

Bitcoin treasury companies have seen a record-breaking 2025 so far, but CryptoQuant data shows momentum has started to slow down. Bitcoin Treasuries May Be Observing A Slowdown In a new post on X, on-chain analytics firm CryptoQuant has discussed how the latest trend is looking when it comes to Bitcoin corporate treasuries. Popularized by Michael […]
Share
Bitcoinist2025/09/18 06:00