[ad_1]
Researchers attributed the recent JumpCloud breach to a branch of the North Korean group Lazarus. Early indications suggest the group was financially driven, primarily targeting cryptocurrency and blockchain companies.
JumpCloud is a directory-as-a-service provider serving more than 180,000 customers, according to its website, including Monday.com, GoFundMe and others. 6sense ranks its platform as the 32nd most popular identity and access management (IAM) solution, with a market share of 0.2%.
On July 12, JumpCloud CISO Robert Phan disclosed in a blog post “a sophisticated nation-state sponsored threat actor who gained unauthorized access to our systems to target a specific small group of our customers.” It was unclear which nation-state until today, when Tom Hegel, senior threat researcher at SentinelOne, linked the hacker-controlled infrastructure to North Korea. Hegel also linked the attack to a social engineering campaign identified by Github on July 18.
Crowdstrike, working directly with JumpCloud, today offered a more specific attribution to Reuters, naming a subsector of the Lazarus Group they track as “Labyrinth Chollima.”
Now, working with victims of the breach, Mandiant researchers are completing the puzzle even further. In upcoming research, the cybersecurity firm plans to reveal that hackers primarily target the Web3 industry, stealing credentials from crypto and blockchain companies for later attacks.
Timeline of JumpCloud Breaches
JumpCloud was first notified of suspicious activity on June 27 at 15:13 UTC. It happened “over an internal orchestration system that we traced to a sophisticated spear-phishing campaign,” wrote Pham, which began the previous week, June 22.
The attackers had managed to hit “a specific area of our infrastructure”, admitted Pham, successfully carrying out a data injection attack against the company’s command framework. To mitigate the damage, he wrote, “we rotated credentials, rebuilt infrastructure, and took a number of other steps to further secure our network and perimeter. Additionally, we activated our prepared incident response plan and worked with our incident response (IR) partner to scan all systems and logs for potential activity. It was also at this time, as part of our IR plan, that we contacted and engaged law enforcement in our investigation.”
The first evidence of the client’s compromise was spotted at 03:35 UTC on July 5. The company notified affected customers and later that day launched a forced rotation of all admin API keys.
JumpCloud has not yet revealed how many customers were affected by its breach, or by how much. Pham noted that “the attack vector used by the threat actor has been mitigated.”
How the IoCs pointed the finger at the DPRK
JumpCloud had identified its hackers as a nation-state entity. But which one?
The proof was in the indicators of compromise (IOCs) made public. With them, Hegel says, “I can start diving into the IP addresses themselves, trying to understand their profile, seeing what else is being used on that server, what those domains are talking about.” In one instance, Hegel connected an IP address to a domain identified in another social engineering campaign that GitHub attributed to North Korean hackers.
Hegel slowly mapped the command infrastructure of attackers, an IP address bound to a domain, a domain bound to a cluster, or a previously known attack.
The attackers left some digital fingerprints like how and when it was saved, as well as “when it resolves to other servers, and other random technical characteristics like the SSL certificate or software running on that server,” Hegel clarifies. “There are a million different attributes that we can use to profile a server’s fingerprint, which in this case overlaps with other North Korean elements.”
Source: Sentinel Laboratories
The image above shows how the two campaigns, and the different domains and IPs they contain, are connected. “Putting it all together, you understand that it’s a big set of infrastructure. Everything is connected,” says Hegel. “And who do I see operating from this infrastructure? At this point, we see it overlapping with several groups from other Lazarus campaigns.”
Targeting the Crypto Industry
As an IAM service provider, JumpCloud provides a direct path for hackers to steal corporate credentials that could prove useful for later attacks. But what kind of attacks did Lazarus intend to pursue this time?
There too, in retrospect, there were clues. As in JumpCloud’s blog post, where Pham noted how the attack, far from being a general spray-and-pray campaign, “was extremely targeted and limited to specific customers.”
And there was the GitHub attack that Hegel linked to. In this case, “many of these targeted accounts are connected to the blockchain, cryptocurrency, or online gaming sectors,” Github noted in its blog post.
In a statement on JumpCloud attackers shared with Dark Reading, Mandiant revealed, “with great confidence that it is a cryptocurrency-focused element within the Reconnaissance General Bureau (RGB) of the DPRK, targeting companies with cryptocurrency verticals to obtain credentials and reconnaissance data,” the provider wrote. “This is a financially motivated threat actor that we have seen increasingly target the cryptocurrency industry and various blockchain platforms.”
According to Austin Larsen, Senior Mandiant Incident Response Consultant at Google Cloud, Mandiant has not identified any financial consequences for the JumpCloud victims it has worked with. However, this only appears to be because “this campaign was primarily focused on obtaining identification information from priority targets and reconnaissance data for future intrusions,” he says. In at least one case, in fact, the team “identified evidence that the actor successfully achieved their goal of collecting credentials from priority targets.”
North Korean hackers targeting the crypto industry to fund the Kim regime is nothing new. But the JumpCloud attack reiterates how refined and successful their ongoing strategy has become. “They are very creative”, thinks Hegel. “It really shows their understanding and desire to carry out multi-layered attacks on the supply chain.”
|
Sources 2/ https://www.darkreading.com/attacks-breaches/north-korean-attackers-targeted-crypto-companies-in-jumpcloud-breach The mention sources can contact us to remove/changing this article |
[ad_2]