Stock Market News

Exclusive-North Korea hackers breached US IT company in bid to steal crypto -sources

2023.07.20 15:31

2/2

© Reuters. Miniatures of people with computers are seen in front of North Korea flag in this illustration taken July 19, 2023. REUTERS/Dado Ruvic/Illustration

2/2

By Christopher Bing and Raphael Satter

WASHINGTON (Reuters) – A North Korean government-backed hacking group penetrated an American IT management company and used it as a springboard to target cryptocurrency companies, according to two sources familiar with the matter.

The hackers broke into Louisville, Colorado-based JumpCloud in late June and used their access to the company’s systems to target its cryptocurrency company clients in an effort to steal digital cash, the sources said.

The hack shows how North Korean cyber spies, once content with going after crypto companies one at a time, are now tackling companies that can give them access to multiple sources of bitcoin and other digital currencies.

JumpCloud, which acknowledged the hack in a blog post last week and blamed it on a “sophisticated nation-state sponsored threat actor,” did not respond to Reuters’ questions about who was behind the hack and which clients were affected.

A JumpCloud spokesperson said fewer than five customers had been impacted. Reuters could not ascertain whether any digital currency was ultimately stolen as a result of the hack.

Cybersecurity firm CrowdStrike Holdings (NASDAQ:), which is working with JumpCloud to investigate the breach, confirmed that “Labyrinth Chollima” – the name it gives to a particular squad of North Korean hackers – was behind the breach.

CrowdStrike Senior Vice President for Intelligence Adam Meyers declined to comment on what the hackers were seeking, but noted that they had a history of targeting cryptocurrency.

“One of their primary objectives has been generating revenue for the regime,” he said.

Pyongyang’s mission to the United Nations in New York did not immediately respond to a request for comment. North Korea has previously denied organizing digital currency heists, despite voluminous evidence – including U.N. reports – to the contrary.

Independent research backed CrowdStrike’s allegation.

Cybersecurity researcher Tom Hegel, who wasn’t involved in the investigation, told Reuters that the JumpCloud intrusion was the latest of several recent breaches that showed how the North Koreans have become adept at “supply chain attacks,” or elaborate hacks that work by compromising software or service providers in order to steal data – or money – from users downstream.

“North Korea in my opinion is really stepping up their game,” said Hegel, who works for U.S. firm SentinelOne (NYSE:).

In a blog post to be published Thursday, Hegel said the digital indicators published by JumpCloud tied the hackers to activity previously attributed to North Korea.

The U.S. cyber watchdog agency CISA and the FBI declined to comment.

The hack on JumpCloud – whose products are used to help network administrators manage devices and servers – first surfaced publicly earlier this month when the firm emailed customers to say their credentials would be changed “out of an abundance of caution relating to an ongoing incident.”

In the blog post that acknowledged that the incident was a hack, JumpCloud traced the intrusion back to June 27. The cybersecurity-focused podcast Risky Business earlier this week cited two sources as saying that North Korea was a suspect in the intrusion.

Labyrinth Chollima is one of North Korea’s most prolific hacking groups and is said to be responsible for some of the isolated country’s most daring and disruptive cyber intrusions. Its theft of cryptocurrency has led to the loss of eye-watering sums: Blockchain analytics firm Chainalysis said last year that North Korean-linked groups stole an estimated $1.7 billion worth of digital cash across multiple hacks.

In a statement sent to Reuters following this article’s publication, Mandiant, a U.S. cybersecurity company owned by Google (NASDAQ:), said that they were currently assisting a “downstream victim” of JumpCloud and had also determined the hackers responsible worked for North Korea’s Reconnaissance General Bureau (RGB), the country’s primary foreign intelligence agency.

CrowdStrike’s Meyers said Pyongyang’s hacking squads should not be underestimated.

“I don’t think this is the last we’ll see of North Korean supply chain attacks this year,” he said.

Source link

Related Articles

Back to top button
bitcoin
Bitcoin (BTC) $ 98,797.47 1.02%
ethereum
Ethereum (ETH) $ 3,487.99 5.63%
tether
Tether (USDT) $ 1.00 0.04%
solana
Solana (SOL) $ 261.71 2.46%
bnb
BNB (BNB) $ 675.50 8.94%
xrp
XRP (XRP) $ 1.55 9.36%
dogecoin
Dogecoin (DOGE) $ 0.464012 16.65%
cardano
Cardano (ADA) $ 1.10 23.05%
usd-coin
USDC (USDC) $ 1.00 0.01%
staked-ether
Lido Staked Ether (STETH) $ 3,487.73 5.66%
tron
TRON (TRX) $ 0.222939 12.22%
avalanche-2
Avalanche (AVAX) $ 42.76 11.29%
shiba-inu
Shiba Inu (SHIB) $ 0.000028 11.72%
the-open-network
Toncoin (TON) $ 6.15 12.75%
wrapped-steth
Wrapped stETH (WSTETH) $ 4,111.78 5.16%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 98,649.43 1.11%
stellar
Stellar (XLM) $ 0.453727 55.52%
polkadot
Polkadot (DOT) $ 8.19 33.81%
chainlink
Chainlink (LINK) $ 17.60 16.78%
bitcoin-cash
Bitcoin Cash (BCH) $ 539.59 13.10%
sui
Sui (SUI) $ 3.65 3.66%
weth
WETH (WETH) $ 3,497.23 5.92%
pepe
Pepe (PEPE) $ 0.000022 8.91%
leo-token
LEO Token (LEO) $ 8.63 1.40%
near
NEAR Protocol (NEAR) $ 6.41 14.69%
litecoin
Litecoin (LTC) $ 102.90 15.76%
aptos
Aptos (APT) $ 12.98 9.66%
uniswap
Uniswap (UNI) $ 10.83 15.05%
wrapped-eeth
Wrapped eETH (WEETH) $ 3,675.99 5.76%
hedera-hashgraph
Hedera (HBAR) $ 0.150328 15.50%
internet-computer
Internet Computer (ICP) $ 11.47 17.11%
crypto-com-chain
Cronos (CRO) $ 0.201336 8.47%
usds
USDS (USDS) $ 1.00 0.21%
polygon-ecosystem-token
POL (ex-MATIC) (POL) $ 0.582762 28.75%
ethereum-classic
Ethereum Classic (ETC) $ 30.87 12.44%
render-token
Render (RENDER) $ 8.02 12.04%
kaspa
Kaspa (KAS) $ 0.161249 9.79%
bittensor
Bittensor (TAO) $ 542.97 11.13%
bonk
Bonk (BONK) $ 0.000051 2.64%
ethena-usde
Ethena USDe (USDE) $ 1.00 0.09%
fetch-ai
Artificial Superintelligence Alliance (FET) $ 1.44 16.69%
arbitrum
Arbitrum (ARB) $ 0.874702 9.96%
whitebit
WhiteBIT Coin (WBT) $ 24.68 0.04%
vechain
VeChain (VET) $ 0.043896 35.97%
dogwifcoin
dogwifhat (WIF) $ 3.54 12.39%
dai
Dai (DAI) $ 1.00 0.12%
mantra-dao
MANTRA (OM) $ 3.78 3.46%
cosmos
Cosmos Hub (ATOM) $ 8.26 17.01%
blockstack
Stacks (STX) $ 2.12 12.27%
filecoin
Filecoin (FIL) $ 5.30 14.85%