CoinsPaid Blames North Korean Hackers for $37 Million Cryptocurrency Heist

Cryptocurrency payments firm CoinsPaid says North Korean hacking group Lazarus is likely responsible for the theft of approximatively $37 million in cryptocurrency.

Based in Estonia, the company provides crypto services and personal wallets, allowing businesses to accept payments in cryptocurrency. It also offers a SaaS solution and an OTC trading platform.

Following downtime earlier this week, CoinsPaid announced that, on July 22, it fell victim to a sophisticated cyberattack that resulted in the theft of $37.3 million.

“As a result of a hybrid attack on our company, which involved elements of social engineering, aggressive bribery attempts of critical personnel, and attacks on numerous internet-accessible applications, the attackers managed to identify a vulnerable application that was not directly involved in service provision,” the company said on Thursday.

The vulnerability allowed the attackers to compromise CoinsPaid infrastructure supporting transactions and to modify the data of transactions, the company says.

CoinsPaid was able to identify the attack and address the vulnerability before the attackers could steal more funds, and says that client funds were not affected by the incident.

“We believe Lazarus expected the attack on CoinsPaid to be much more successful. In response to the attack, the company’s dedicated team of experts has worked tirelessly to fortify our systems and minimize the impact, leaving Lazarus with a record-low reward,” CoinsPaid said.

Advertisement. Scroll to continue reading.

The attack impacted the platform’s availability, as the company suspended automatic transactions and began moving the systems to new infrastructure. Systems have been restored to normal operations and processing of transactions has resumed, but CoinsPaid expects impact on its revenue following the incident.

Believed to be operating on behalf of the North Korean government, Lazarus Group has been blamed for multiple high-profile cryptocurrency thefts and is said to have stolen more than $1 billion in crypto assets over the past two years.

This year alone, Lazarus has been blamed for the $100 million Horizon Bridge heist, for the theft of $35 million in cryptocurrency from Atomic Wallet, and for the recent $23 million cryptocurrency heist at payment processor Alphapo.

Related: US Sanctions North Korean University for Training Hackers

Related: North Korea’s Lazarus Targets Energy Firms With Three RATs

Related: North Korea APT Lazarus Targeting Chemical Sector

https://www.securityweek.com/coinspaid-blames-north-korean-hackers-for-37-million-cryptocurrency-heist/




CardioComm Takes Systems Offline Following Cyberattack

Canadian heart monitoring and medical electrocardiogram solutions provider CardioComm this week announced it has taken systems offline following a cyberattack.

The attack, the company says, impacted its production server environments and has an impact on its business operations. Visitors to the company’s website are informed that CardioComm services are currently offline.

“CardioComm’s business operations will be impacted for several days and potentially longer depending how quickly the company is able to restore its data and re-establishes its production server environments,” the company announced.

According to CardioComm, it has no evidence that customer health information was compromised in the attack, mainly because its software runs on each client’s systems.

“Further, CardioComm does not collect patient health information from its clients. The company has initiated identity theft precautions should any employee personal information have been compromised to minimize the impact on its staff,” CardioComm said.

The incident, the company noted, might also impact its ability to finalize required filings in response to a Cease Trade Order issued by the Ontario Securities Commission, which resulted in the suspension of its shares trading, imposed by the TSX Venture Exchange.

Although CardioComm did not share details on the type of cyberattack it fell victim to, it is possible that ransomware might have been involved. Typical incident response in the event of a ransomware attack involves taking systems offline to contain the incident.

Advertisement. Scroll to continue reading.

CardioComm provides hospital, physician, and consumer device software for recording, analyzing, and managing electrocardiograms for the diagnosis of cardiac patients.

Related: JumpCloud Cyberattack Linked to North Korean Hackers

Related: Recycling Giant Tomra Takes Systems Offline Following Cyberattack

Related: Critical Infrastructure Services Firm Ventia Takes Systems Offline Due to Cyberattack

https://www.securityweek.com/cardiocomm-takes-systems-offline-following-cyberattack/




Maritime Cyberattack Database Launched by Dutch University

The NHL Stenden University of Applied Sciences in the Netherlands recently announced the launch of a database tracking cyberattacks and other cyber incidents impacting the maritime sector.

The Maritime Cyber Attack Database, or MCAD, currently tracks more than 160 incidents recorded since 2001. The database is publicly accessible at maritimecybersecurity.nl and it’s continuously updated and improved. 

The project is led by Dr Stephen McCombie, professor of maritime IT security at NHL Stenden. The database was created in collaboration with students, using open source information. 

The goal of the project is to raise awareness and provide data for future maritime cybersecurity research. The database will also be used to conduct analysis on subsets of the data and highlight trends. 

[ Read: The Vulnerable Maritime Supply Chain – a Threat to the Global Economy ]

The Maritime Cyber Attack Database can also be used to create realistic cyber incident simulations, its creators said.

The database currently includes many attacks involving ransomware, as well as insider incidents and spoofing attacks.   

Advertisement. Scroll to continue reading.

Incidents have been recorded worldwide, but many impacted ports around Europe, East Asia and the United States. 

Related: Malvuln Project Catalogs 260 Vulnerabilities Found in Malware

Related: University Project Cataloged 1,100 Ransomware Attacks on Critical Infrastructure

https://www.securityweek.com/maritime-cyberattack-database-launched-by-dutch-university/




Ivanti Zero-Day Vulnerability Exploited in Attack on Norwegian Government

A new zero-day vulnerability affecting a product of US-based enterprise software provider Ivanti has been exploited in an attack aimed at the Norwegian government. 

Norwegian authorities announced on Monday that a dozen government ministries had been targeted in a cyberattack involving a previously unknown vulnerability. 

The country’s National Security Authority later clarified that the attack involved the exploitation of CVE-2023-35078, a zero-day vulnerability impacting Ivanti’s Endpoint Manager Mobile (EPMM), formerly known as MobileIron Core. 

EPMM is a widely used mobile management software engine that enables IT teams to set policies for mobile devices, applications, and content.

According to an advisory published on Monday by Ivanti for CVE-2023-35078, the flaw is an unauthenticated API access issue that can be exploited by remote threat actors “to potentially access users’ personally identifiable information and make limited changes to the server”.

“We have received information from a credible source indicating exploitation has occurred. We continue to work with our customers and partners to investigate this situation,” Ivanti said. “We are only aware of a very limited number of customers that have been impacted.”

The authentication bypass vulnerability has been rated ‘critical’ and it impacts all supported versions, including 11.10, 11.9 and 11.8, as well as older releases. The vendor has rushed to release a patch and organizations have been advised to install it as soon as possible due to how easy it is to exploit the flaw. 

Advertisement. Scroll to continue reading.

Security researcher Kevin Beaumont has set up a honeypot to monitor CVE-2023-35078 and he has already been seeing exploitation attempts.  

There are many internet-exposed systems, particularly in the United States and Europe. 

The vendor, whose offering includes cybersecurity products, has faced criticism for initially deciding not to make its advisory public — it was initially behind a paywall and exploitation information was hidden. 

The US Cybersecurity and Infrastructure Security Agency (CISA) has also released an alert, clarifying that the zero-day can be exploited by an attacker with access to specific API paths to obtain information such as name, phone number and other mobile device details.

The configuration changes that can be made by an attacker include creating an admin account that can make other modifications to the targeted system. 

CISA’s Known Exploited Vulnerabilities Catalog currently lists nine Ivanti product flaws — it does not include the latest zero-day. All of these security holes impact Pulse Connect Secure and MobileIron products, which Ivanti acquired in 2020. 

Related: Citrix Zero-Day Exploited Against Critical Infrastructure Organization

Related: Adobe Releases New Patches for Exploited ColdFusion Vulnerabilities

Related: Zero-Day Vulnerability Exploited to Hack Barracuda Email Security Gateway Appliances

https://www.securityweek.com/ivanti-zero-day-vulnerability-exploited-in-attack-on-norwegian-government/




Los Angeles SIM Swapper Pleads Guilty to Cybercrime Charges

A Los Angeles man has pleaded guilty to using SIM swapping to perpetrate multiple cybercrime schemes targeting hundreds of victims.

Between April 2019 and February 2023, the man, Amir Hossein Golshan, 24, engaged in account takeovers, Zelle payment fraud, and Apple support impersonation, causing roughly $740,000 in losses to his victims.

According to the plea agreement, in December 2021, relying on SIM swapping – a technique in which a threat actor convinces a phone carrier to transfer a phone number to a SIM card in the attacker’s control – Golshan took over the Instagram account of an influencer with over 100,000 followers.

Using the unauthorized access to the account, he contacted the victim’s friends impersonating the influencer, asking them to send money via Zelle, PayPal, and other platforms, obtaining thousands of dollars from the unsuspecting victims.

He also locked the influencer out of her accounts and sent her messages demanding a $2,000 ransom for returning control of the accounts.

According to the plea agreement, Golshan admitted to using SIM swapping against two other victims in January 2022. After taking control of one of the victims’ social media accounts, he demanded a $5,000 ransom, threatening to release personal videos and photos.

Golshan targeted roughly 500 individuals in SIM swapping and Zelle fraud schemes, receiving approximately $82,000 in payments from his victims.

Advertisement. Scroll to continue reading.

Court documents show that the defendant also impersonated Apple support personnel to gain access to victim accounts and steal NFTs, cryptocurrency, and other digital goods, defrauding five victims of between $2,000 and $389,000 each.

Golshan pleaded guilty to unauthorized computer access, access to a computer to defraud, and wire fraud. Scheduled for sentencing on November 27, he faces up to five years in prison for the computer access counts and up to 20 years in prison for wire fraud.

Related: Hacker Conversations: Inside the Mind of Daniel Kelley, ex-Blackhat

Related: Russian Admits in US Court to Laundering Money for Ryuk Ransomware Gang

Related: SIM Swapper Who Stole $20 Million Sentenced to Prison

https://www.securityweek.com/los-angeles-sim-swapper-pleads-guilty-to-cybercrime-charges/




Industrial Organizations in Eastern Europe Targeted by Chinese Cyberspies

A China-linked cyberspy group appears to be behind a campaign targeting industrial organizations in Eastern Europe, cybersecurity firm Kaspersky reported last week.

The attacks have been linked to APT31, a group believed to be sponsored by the Chinese government that is also known as Zirconium, Judgement Panda, Bronze Vinewood and Red Keres. The threat actor has focused on operations whose goal is to steal valuable intellectual property from victims. 

While the targets of the campaign analyzed by Kaspersky were industrial organizations, the company told SecurityWeek there is no indication that the hackers targeted industrial control systems (ICS).

“We do not have any evidence that the attackers could have anything in addition to data theft as their goal in this campaign,” Kaspersky said. 

The attacks were observed in 2022 and the cybersecurity firm recently concluded its investigation into the campaign. 

The hackers attempted to establish permanent channels for data exfiltration, including for information stored on air-gapped systems, which they targeted through malware-infected removable drives.

The attackers used improved variants of a previously known malware named FourteenHi, which enables the attackers to upload or download files, run commands, and initialize a reverse shell.

Advertisement. Scroll to continue reading.

The new variants were designed to specifically target the infrastructure of industrial organizations.

In addition, the cyberspies leveraged a new malware implant dubbed MeatBall, which provides extensive remote access capabilities. 

The attackers exploited DLL hijacking vulnerabilities affecting legitimate applications to load some of their malware. 

“To exfiltrate data and deliver next-stage malware, the threat actor (or actors) abuse(s) a cloud-based data storage, e.g., Dropbox or Yandex Disk, as well as a service used for temporary file sharing. They also use C2 deployed on regular virtual private servers (VPS),” Kaspersky explained.

The cybersecurity firm’s report includes technical details on these attacks, including indicators of compromise (IoCs) and tactics, techniques, and procedures (TTPs). 

Related: Chinese Cyberspy Group APT31 Starts Targeting Russia

Related: EU Organizations Warned of Chinese APT Attacks

Related: China-Linked APT15 Targets Foreign Ministries With ‘Graphican’ Backdoor

https://www.securityweek.com/industrial-organizations-in-eastern-europe-targeted-by-chinese-cyberspies/




Prompt Hacking: Vulnerabilità dei Language Model

Introduzione

Gli attacchi ai LM (Language Model) come la prompt injection e la prompt leaking possono essere paragonati alle SQL injection nel contesto della sicurezza informatica. Mentre le SQL injection sfruttano le vulnerabilità dei sistemi di gestione dei database per inserire codice dannoso all’interno delle query SQL, gli attacchi ai LM prendono di mira i modelli linguistici e cercano di manipolare l’output generato. In entrambi i casi, gli aggressori cercano di influenzare il comportamento del sistema iniettando input dannosi o modificando il funzionamento.

Prompt Injection: Manipolazione dell’Output dei LLM

La prompt injection è una tecnica che consente agli hacker di dirottare l’output di un LM. In questo modo è possibile aggiungere contenuti maligni o non intenzionali a un prompt al fine di manipolare l’output del modello. Questa vulnerabilità si manifesta quando un testo non attendibile viene incluso nel prompt, come ad esempio nel caso in cui un attaccante possa creare un prompt che inganni il modello facendogli ignorare la parte legittima a favore del testo iniettato.

Questo mette in luce il potenziale uso errato della prompt injection per diffondere informazioni false o generare risposte inappropriate.

L’azienda remoteli.io aveva un modello linguistico (LLM) che rispondeva ai post su Twitter riguardanti il lavoro da remoto. Gli utenti di Twitter si sono velocemente accorti che potevano inserire il proprio testo nel bot per fargli dire ciò che desideravano.

Questo avviene perché il tweet dell’utente viene unito al prompt utilizzato da remoteli per formare il prompt finale, che viene poi utilizzato dal LLM per generare la risposta. Ciò significa che qualsiasi testo iniettato dall’utente di Twitter verrà inserito nel LLM.

Si pensi come le conseguenze di questa vulnerabilità potrebbero essere impattanti se venisse attaccato ad esempio un chatbot di una banca e venisse detto al modello di ignorare le istruzioni dategli in precedenza e riportare un indirizzo IBAN al quale effettuare tutti i pagamenti, o un numero di telefono di assistenza diverso, in possesso dell’attaccante.

Prompt Leaking: Estrazione di Informazioni Sensibili

Il prompt leaking è una forma di prompt hacking che comporta l’estrazione di informazioni sensibili o confidenziali dalle risposte dei LLM. In alcuni casi, gli utenti desiderano mantenere segreti i loro prompt, come ad esempio un’azienda di formazione che potrebbe voler utilizzare un prompt specifico per spiegare argomenti complessi, ma se questo prompt venisse leaked, chiunque potrebbe utilizzarlo senza seguire il processo previsto dall’azienda.

Il prompt leaking può avere varie implicazioni come è stato dimostrato da un caso riguardante writesonic(.)com. L’azienda che si propone come alternativa a Chat-GPT, l’attuale LLM più utilizzato, è di fatto risultata vulnerabile ed è stato possibile scoprire il prompt utilizzato. Link al post completo (https://www.linkedin.com/feed/update/urn:li:activity:7069314602613784576/ ).

Infatti fornendo un frammento del prompt utilizzato, è stato possibile recuperare il resto del prompt senza l’autenticazione adeguata.

Il prompt leaking rappresenta quindi un rischio significativo, specialmente in scenari in cui vengono utilizzati prompt complessi e di lunga durata, come nelle startup basate su GPT-3/4, dove l’intero business gira attorno alla segretezza del prompt; come ad esempio vizgpt(.)ai, un servizio a pagamento che consente di creare visualizzazioni grafiche utilizzando una chat, anch’essa vulnerabile al prompt leaking. Link al post completo (https://www.linkedin.com/feed/update/urn:li:activity:7084854101997498368/)

Jailbreaking: Bypass delle Funzionalità di Sicurezza e Moderazione

Il jailbreaking si riferisce al processo di utilizzo della prompt injection per aggirare le funzionalità di sicurezza e moderazione implementate dai creatori del LLM. Queste sono di fatti fondamentali per impedire ai LLM di generare risposte controverse, violente, sessuali o illegali. Tuttavia, gli hacker possono sfruttare le vulnerabilità del modello per eludere le restrizioni, consentendo loro di porre domande o ottenere risposte senza limitazioni.

I metodi di jailbreaking spesso implicano oltre al convincimento del LLM che determinate situazioni sfuggano ai limiti etici del modello o che l’utente abbia un’autorità superiore. Ad esempio, fingendo di essere un attore in un ruolo specifico, il modello potrebbe assumere che non esista alcun rischio plausibile, producendo risposte non sicure. Altre tecniche includono l’assunzione di responsabilità, il ragionamento logico e l’attribuzione di privilegi superiori all’utente (modalità sudo). Questi metodi di jailbreaking mettono alla prova la capacità dei LLM di rispettare le linee guida di sicurezza ed etiche.

In questo esempio di “Character Roleplay”, l’attaccante mostra uno scenario di recitazione tra due persone che discutono di una rapina, facendo assumere a ChatGPT il ruolo del personaggio. Come attore, si sottintende che il danno plausibile non esista. Pertanto, ChatGPT sembra assumere che sia sicuro seguire l’input dell’utente fornito su come entrare in una casa.

Link al post originale (https://twitter.com/m1guelpf/status/1598203861294252033)

Difesa contro il Prompt Hacking

Per proteggersi dal prompt hacking, è fondamentale adottare misure difensive. Queste includono:

  • Difese basate sui prompt: analizzare attentamente e convalidare i prompt per impedire l’iniezione di contenuti maligni o non intenzionali.
  • Monitoraggio regolare: monitorare costantemente il comportamento e gli output dei LLM per individuare attività insolite o segni di prompt hacking.
  • Audit di sicurezza: effettuare audit di sicurezza periodici per individuare vulnerabilità e rafforzare la sicurezza complessiva dei LLM.

Prendere misure proattive per proteggersi dal prompt hacking è fondamentale per salvaguardare l’integrità e l’affidabilità dei LLM, soprattutto considerando la crescente diffusione e influenza in vari ambiti.

Bibliografia

  1. Chase, H. (2022). adversarial-prompts. [Online]. Disponibile su: https://github.com/hwchase17/adversarial-prompts.
  2. Perez, F., & Ribeiro, I. (2022). Ignore Previous Prompt: Attack Techniques For Language Models. arXiv. [Online]. Disponibile su: https://doi.org/10.48550/ARXIV.2211.09527.
  3. Brundage, M. (2022). Lessons learned on Language Model Safety and misuse. In OpenAI. OpenAI. [Online]. Disponibile su: https://openai.com/blog/language-model-safety-and-misuse/.
  4. LearnPrompting.org. (s.d.). Category: Prompt Hacking. [Online]. Disponibile su: https://learnprompting.org/docs/category/-prompt-hacking.

Articolo a cura di Giacomo Arienti e Simone Rizzo

Profilo Autore

Giacomo Arienti è uno studente di Ingegneria e Scienze Informatiche con un’ampia esperienza nel campo della sicurezza informatica. Attualmente, lavora come Full Stack Developer, possedendo competenze approfondite nella progettazione e nello sviluppo di applicazioni web.

La sua passione per la cybersecurity è iniziata grazie alla partecipazione alle Olimpiadi Italiane di Cybersecurity, dove ha ottenuto un notevole successo posizionandosi nella top 10 nazionale in entrambe le sue partecipazioni.

Parallelamente alla sua esperienza nel settore della sicurezza informatica, Giacomo ha sviluppato un forte interesse per il mondo dell’intelligenza artificiale.

La missione di Giacomo è quella di rendere la cybersecurity accessibile a tutti e di sensibilizzare le persone sui rischi connessi all’utilizzo delle tecnologie digitali. Ha intrapreso iniziative per condividere le sue conoscenze attraverso workshop e conferenze, mirando a diffondere una maggiore consapevolezza riguardo alle minacce informatiche e alle strategie di protezione.

Profilo Autore

Simone Rizzo è un esperto di Intelligenza Artificiale con una laurea magistrale in Intelligenza Artificiale ottenuta presso l’Università di Pisa. Ha una solida esperienza come AI engineer nel settore della computer vision applicata all’auto a guida autonoma. La sua passione per la ricerca si concentra principalmente sulla spiegabilità dei modelli e sulla privacy nell’ambito del machine learning.

Simone è il fondatore e CEO di Inferentia, un’azienda di consulenza specializzata nell’applicazione dell’Intelligenza Artificiale. L’azienda offre servizi di consulenza e sviluppo di soluzioni AI personalizzate per diverse industrie.

Oltre al suo impegno nel mondo degli affari, Simone è un appassionato divulgatore scientifico su TikTok. Utilizzando il suo talento nel semplificare concetti complessi, condivide informazioni sull’Intelligenza Artificiale con un vasto pubblico, contribuendo a diffondere la consapevolezza e l’interesse verso questa disciplina in rapida evoluzione.
La sua missione è quella di rendere l’Intelligenza Artificiale accessibile a tutti, spiegando il suo impatto e le sue potenzialità nel mondo moderno.

Condividi sui Social Network:

https://www.ictsecuritymagazine.com/articoli/prompt-hacking-vulnerabilita-dei-language-model/




Russia Seeks 18 Years in Jail for Founder of Cybersecurity Firm

A Russian prosecutor on Friday requested an 18-year prison sentence for Ilya Sachkov, founder of one of the country’s top
cybersecurity firms, on treason charges.

Sachkov, 37, co-founded the Group-IB cybersecurity firm in 2003. It specializes in the detection and prevention of cyberattacks and works with Interpol and several other global institutions.

“State prosecutors requested that Sachkov be sentenced to 18 years in prison,” his lawyer Sergei Afanasyev was quoted as saying by Russian news agencies.

A Moscow court is expected to announce its verdict on July 26.

His arrest in 2021 came after US President Joe Biden raised concerns with Russian President Vladimir Putin that Moscow is allowing cybercrime directed at Western countries to flourish in the country.

Treason cases in Russia are typically classified and heard behind closed doors.

Group-IB has said its employees were “confident in their manager’s innocence and honest business reputation”.

Advertisement. Scroll to continue reading.

Sachkov co-founded Group-IB when he was just 17 and he was featured on the Forbes “30 under-30” list of tech entrepreneurs in 2016.

Three years later he received an “innovative breakthrough” award from Putin “for developments in the field of identifying and preventing cyberthreats”, according to the Kremlin.

https://www.securityweek.com/russia-seeks-18-years-in-jail-for-founder-of-cybersecurity-firm/




GitHub Warns of North Korean Social Engineering Attacks Targeting Tech Firm Employees

A North Korean threat actor has been observed targeting employees at technology firms in a new low-volume social engineering campaign, Microsoft-owned code hosting platform GitHub reports.

As part of the observed attacks, employees are invited to collaborate on GitHub repositories that contain software fetching malicious NPM packages meant to infect the intended victims’ computers with additional malware.

“Many of these targeted accounts are connected to the blockchain, cryptocurrency, or online gambling sectors. A few targets were also associated with the cybersecurity sector. No GitHub or npm systems were compromised in this campaign,” the code hosting platform says.

GitHub is confident that the ongoing campaign is perpetrated by a North Korean threat actor tracked as Jade Sleet, and which is also known as TraderTraitor.

To orchestrate the attacks, Jade Sleet impersonates a developer or recruiter, creating fake persona accounts on GitHub, LinkedIn, Slack, and Telegram, or taking control of legitimate accounts.

These accounts are then used to contact employees at tech firms, which are invited to collaborate on a repository. The threat actor then convinces the victim to clone the repository and execute it on their machine, leading to malware infection.

“The threat actor often publishes their malicious packages only when they extend a fraudulent repository invitation, minimizing the exposure of the new malicious package to scrutiny,” GitHub explains.

Advertisement. Scroll to continue reading.

In some cases, messaging services or file sharing platforms may be used to deliver the malicious packages and initiate the infection chain.

GitHub says it has suspended the NPM and GitHub accounts associated with the attacks and also filed abuse reports for the identified domains that were still available.

Previous iterations of the TraderTraitor campaign JavaScript applications leveraging Node.js and the Electron framework were used to infect victims with the Manuscrypt RAT.

Similar activity was reported by Phylum in late June and by SentinelOne on Thursday, in association with the recent cyberattack on JumpCloud.

Related: US, South Korea Detail North Korea’s Social Engineering Techniques

Related: US Sanctions North Korean University for Training Hackers

Related: North Korean Hackers Target Mac Users With New ‘RustBucket’ Malware

https://www.securityweek.com/github-warns-of-north-korean-social-engineering-attacks-targeting-tech-firm-employees/




JumpCloud Cyberattack Linked to North Korean Hackers

The cyberattack that directory, identity, and access management company JumpCloud fell victim to in late June can be attributed to North Korean advanced persistent threat (APT) activity, cybersecurity company SentinelOne says.

JumpCloud revealed last week that the attack started on June 22 with a spear-phishing email campaign, and that it resulted in data being injected into its commands framework a few weeks later.

Attributing the incident to a “sophisticated nation-state sponsored threat actor”, the company announced that the attack was extremely targeted, focusing on a limited set of customers.

JumpCloud did not share specific information on the number of impacted customers, nor on the type of data compromised in the attack. The company provides solutions to over 180,000 organizations.

“JumpCloud recently experienced a cybersecurity incident that impacted a small and specific set of our customers. Upon detecting the incident, we immediately took action based on our incident response plan to mitigate the threat, secure our network and perimeter, communicate with our customers, and engage law enforcement,” a JumpCloud spokesperson told SecurityWeek, responding to an inquiry.

After analyzing the indicators of compromise (IoCs) that JumpCloud shared last week, SentinelOne identified links to North Korean state-sponsored activities.

“The IOCs are linked to a wide variety of activity we attribute to DPRK, overall centric to the supply chain targeting approach seen in previous campaigns,” SentinelOne says.

Advertisement. Scroll to continue reading.

The IoCs that JumpCloud shared allowed the cybersecurity firm to map out the attackers’ infrastructure, identifying domains that were constructed using patterns observed in previous North Korean incidents.

SentinelOne also identified links to various NPM and ‘package’ themed infrastructure, and to infrastructure linked to the TraderTraitor campaign, the 3CX hack, and the AppleJeus operation, all attributed to North Korean hackers.

“It is evident that North Korean threat actors are continuously adapting and exploring novel methods to infiltrate targeted networks. The JumpCloud intrusion serves as a clear illustration of their inclination towards supply chain targeting, which yields a multitude of potential subsequent intrusions,” SentinelOne notes.

Mandiant has also linked the attack to a North Korean threat actor while investigating a downstream victim that was a result of this attack. 

“Mandiant is currently working with a downstream victim that was compromised as a result of JumpCloud intrusion. Based on our initial analysis, Mandiant assesses with high confidence that this is a cryptocurrency-focused element within the DPRK’s Reconnaissance General Bureau (RGB), targeting companies with cryptocurrency verticals to obtain credentials and reconnaissance data,” Austin Larsen, Mandiant Senior Incident Response Consultant at Google Cloud, told SecurityWeek.

“This is a financially motivated threat actor that we’ve seen increasingly target the cryptocurrency industry and various blockchain platforms. The blending and sharing of DPRK’s cyber infrastructure makes attribution oftentimes difficult, however targeting remains consistent and we anticipate there are other victims that are dealing with this,” Larsen added.

*updated with information from Mandiant

Related: North Korean Hackers Caught Using Malware With Microphone Wiretapping Capabilities

Related: North Korean Hackers Blamed for $35 Million Atomic Wallet Crypto Theft

Related: US, South Korea Detail North Korea’s Social Engineering Techniques

https://www.securityweek.com/jumpcloud-cyberattack-linked-to-north-korean-hackers/