Kucoin North Korean Hackers Exploit React2Shell Vulnerability in Crypto Sector
Article Content
Browse articles
A group of hackers suspected to be linked to North Korea has targeted cryptocurrency firms, exploiting the React2Shell vulnerability (CVE-2025-55182). The attackers compromised AWS access credentials to infiltrate cloud environments and extract sensitive data from various resources, including S3 and EC2 instances.
Ask AI about this cluster
Answers cite the sources they use
Updated 211d ago How this analysis works
Timeline
2025-12-03
CVE-2025-55182 published
2025-12-05
CVE-2025-55182 added to CISA KEV for active exploitation
2025-12-14
First public PoC for CVE-2025-55182
2026-03-09
Security firm Ctrl-Alt-Intel reports on North Korean attacks
More articles in this cluster (8)
Following this threat?
Track React2Shell, Ctrl-Alt-Intel and CVE-2025-55182 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Novo Nordisk Data Breach Exploits Hardcoded GitHub Tokens Novo Nordisk suffered a data breach linked to the cyber extortion group FulcrumSec, which exploited hardcoded credentials found in client-side JavaScript across two subdomains. The attackers accessed over 1 terabyte of sensitive data, including experimental drug data and customer records, after gaining entry in June…
Langflow AI Platform Targeted by RCE Exploitation In September 2026, the Langflow AI application-building platform faced significant exploitation attempts targeting CVE-2026-0768, an unauthenticated remote code execution vulnerability. F5 Labs reported 405 requests from 55 distinct source IPs, indicating a coordinated effort to exploit this flaw. The vulnerability…