comScore
Active Stocks
Wed Aug 09 2023 14:45:34
  1. Tata Steel share price
  2. 119.55 1.23%
  1. Tata Motors share price
  2. 619.25 1.98%
  1. Infosys share price
  2. 1,393 0.19%
  1. ITC share price
  2. 455.8 0.74%
  1. Wipro share price
  2. 416.9 0.08%
Business News/ Markets / Cryptocurrency/  North Korean hacking group Labyrinth Chollima breached US IT firm JumpCloud to steal cryptocurrency
Back

North Korean hacking group Labyrinth Chollima breached US IT firm JumpCloud to steal cryptocurrency

JumpCloud said that the hackers broke into the IT firm in late June and used their access to the company’s systems to target ‘fewer than 5’ of its clients

The cybersecurity-focused podcast Risky Business earlier this week cited two sources as saying that North Korea was a suspect in the intrusion. (REUTERS)Premium
The cybersecurity-focused podcast Risky Business earlier this week cited two sources as saying that North Korea was a suspect in the intrusion. (REUTERS)

A hacking group Labyrinth Chollima, backed by North Korean government, penetrated IT management company JumpCloud in the US and used it as a springboard to target cryptocurrency companies, the IT firm said on Thursday.

In a blog post, JumpCloud said that the hackers broke into the IT firm in late June and used their access to the company’s systems to target "fewer than 5" of its clients.

JumpCloud did not identify the customers affected, but cybersecurity firms CrowdStrike Holdings - which is assisting JumpCloud - and Alphabet-owned Mandiant - which is assisting one of JumpCloud's clients - both said the hackers involved were known to focus on cryptocurrency theft.

A Reuters report said two people familiar with the matter confirmed that the JumpCloud clients targeted by the hackers were cryptocurrency companies.

“North Korea in my opinion is really stepping up their game," Tom Hegel, who works for US firm SentinelOne, told Reuters and also independently confirmed Mandiant and CrowdStrike's attribution.

CrowdStrike identified the hackers as "Labyrinth Chollima" - one of several groups alleged to operate on North Korea's behalf. Mandiant said the hackers responsible worked for North Korea's Reconnaissance General Bureau (RGB), its primary foreign intelligence agency.

The hack on JumpCloud – whose products are used to help network administrators manage devices and servers – first surfaced publicly earlier this month when the firm emailed customers to say their credentials would be changed “out of an abundance of caution relating to an ongoing incident." 

In an earlier version of the blog post that acknowledged that the incident was a hack, JumpCloud traced the intrusion back to June 27. The cybersecurity-focused podcast Risky Business earlier this week cited two sources as saying that North Korea was a suspect in the intrusion.

Labyrinth Chollima is one of North Korea’s most prolific hacking groups and is said to be responsible for some of the isolated country’s most daring and disruptive cyber intrusions. Its theft of cryptocurrency has led to the loss of eye-watering sums: Blockchain analytics firm Chainalysis said last year that North Korean-linked groups stole an estimated $1.7 billion worth of digital cash across multiple hacks. 

 (With inputs from Reuters)

 

Catch all the Business News, Market News, Breaking News Events and Latest News Updates on Live Mint. Download The Mint News App to get Daily Market Updates.
More Less
Updated: 21 Jul 2023, 02:01 AM IST
Next Story
Recommended For You
GENIE RECOMMENDS

Get the best recommendations on Stocks, Mutual Funds and more based on your Risk profile!

Let’s get started
Switch to the Mint app for fast and personalized news - Get App
×
userProfile
Get alerts on WhatsApp
Set Preferences My Reads Watchlist Feedback Redeem a Gift Card Logout