Search

North Korean Hacker Group Said to Have Targeted Several US Crypto Firms

JumpCloud acknowledged the hack in a blog post last week and blamed it on a “sophisticated nation-state sponsored threat actor.

Advertisement
Highlights
  • The hackers broke into Louisville, Colorado-based JumpCloud in late June
  • The hack shows how North Korean cyber spies are now tackling companies
  • Cybersecurity firm CrowdStrike Holdings is working to investigate breach
North Korean Hacker Group Said to Have Targeted Several US Crypto Firms

The hack on JumpCloud first surfaced publicly earlier this month when the firm emailed customers

A North Korean government-backed hacking group penetrated an American IT management company and used it as a springboard to target an unknown number of cryptocurrency companies, according to two sources familiar with the matter. 

The hackers broke into Louisville, Colorado-based JumpCloud in late June and used their access to the company's systems to target its cryptocurrency company clients in an effort to steal digital cash, the sources said.

The hack shows how North Korean cyber spies, once content with going after crypto companies one at a time, are now tackling companies that can give them access to multiple sources of bitcoin and other digital currencies.

JumpCloud, which acknowledged the hack in a blog post last week and blamed it on a “sophisticated nation-state sponsored threat actor,” did not answer Reuters' questions about who specifically was behind the hack and which clients were affected. Reuters could not ascertain whether any digital currency was ultimately stolen as a result of the hack.

Cybersecurity firm CrowdStrike Holdings, which is working with JumpCloud to investigate the breach, confirmed that Labyrinth Chollima — the name it gives to a particular squad of North Korean hackers — was behind the breach.

CrowdStrike Senior Vice President for Intelligence Adam Meyers declined to comment on what the hackers were seeking, but noted that they had a history of targeting cryptocurrency targets.

"One of their primary objectives has been generating revenue for the regime," he said.

Pyongyang's mission to the United Nations in New York did not immediately respond to a request for comment. North Korea has previously denied organizing digital currency heists, despite voluminous evidence — including UN reports — to the contrary.

Independent research backed CrowdStrike's allegation. 

Cybersecurity researcher Tom Hegel, who wasn't involved in the investigation, told Reuters that the JumpCloud intrusion was the latest of several recent breaches that showed how the North Koreans have become adept at “supply chain attacks,” or elaborate hacks that work by compromising software or service providers in order to steal data — or money — from users downstream. 

“North Korea in my opinion is really stepping up their game,” said Hegel, who works for US firm SentinelOne.

In a blog post to be published Thursday, Hegel said the digital indicators published by JumpCloud tied the hackers to activity previously attributed to North Korea. 

The US cyber watchdog agency CISA and the FBI declined to comment.

The hack on JumpCloud – whose products are used to help network administrators manage devices and servers – first surfaced publicly earlier this month when the firm emailed customers to say their credentials would be changed “out of an abundance of caution relating to an ongoing incident.” 

In the blog post that acknowledged that the incident was a hack, JumpCloud traced the intrusion back to June 27. The cybersecurity-focused podcast Risky Business earlier this week cited two sources as saying that North Korea was a suspect in the intrusion.

Labyrinth Chollima is one of North Korea's most prolific hacking groups and is said to be responsible for some of the isolated country's most daring and disruptive cyber intrusions. Its theft of cryptocurrency has led to the loss of eye-watering sums: Blockchain analytics firm Chainalysis said last year that North Korean-linked groups stole an estimated $1.7 billion (nearly Rs. 13,900 crore) worth of digital cash across multiple hacks.

CrowdStrike's Meyers said Pyongyang's hacking squads should not be underestimated.

"I don't think this is the last we'll see of North Korean supply chain attacks this year," he said.

© Thomson Reuters 2023


From the Nothing Phone 2 to the Motorola Razr 40 Ultra, several new smartphones are expected to make their debut in July. We discuss all of the most exciting smartphones coming this month and more on the latest episode of Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

 
Show Full Article
Please wait...
Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo F29 5G, Oppo F29 Pro 5G Launched in India: Price, Features
  2. Vivo Y19e With 5,500mAh Battery Launched in India: Price, Offers
  3. iPhone 17 Air Case Leak Hints at Pixel-Like Rear Camera Design
  4. Samsung Expands One UI 7 Rollout to Include Galaxy S21, Galaxy S22 Models
  5. HMD Barbie Phone With 2.8-Inch Display, Themed Accessories Launched in India
  6. Huawei Pura X Foldable Phone With 6.3-Inch 16:10 Inner Display Launched
  7. Google Pixel 9a Uses an Older Modem Compared to Other Pixel 9 Models
  8. Infinix Note 50X 5G Will Be Priced Under Rs. 12,000 in India
  9. Infinix Note 50X 5G Battery, Charging Details Revealed; Price Range Tipped
  10. CMF Phone 2 Alleged Hands-on Renders Suggest Upgraded Rear Camera Setup
  1. Samsung Expands One UI 7 Rollout to Include Galaxy S21, Galaxy S22 Models and Other Phones
  2. Infinix Note 50X 5G Price Details and Chipset Confirmed Ahead of Launch in India
  3. Brahma Anandam Now Streaming on Aha: Everything You Need to Know
  4. A Complete Unknown OTT Release Date: When and Where to Watch Timothée Chalamet’s Biopic
  5. Touch Me Not Telugu OTT Release Date: When and Where to Watch it Online?
  6. Sabdham OTT Release Date: When and Where to Watch Aadhi Pinisetty’s Horror Thriller
  7. Wolf-Rayet 104's Orbit Tilt Reduces Gamma-Ray Burst Threat, Study Finds
  8. Mount Spurr Volcano in Alaska Shows Signs of Possible Eruption
  9. Iguanas Travelled 5,000 Miles to Fiji on Rafts 34 Million Years Ago
  10. Atacama Telescope Reveals Most Detailed Cosmic Microwave Background Yet
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »