iTnews Asia
  • Home
  • News
  • Security

OPSEC "fumble" exposed JumpCloud attackers

OPSEC "fumble" exposed JumpCloud attackers

North Korea’s UNC4889 behind attack, says Mandiant.

By Richard Chirgwin on Jul 26, 2023 11:52AM

The North Korean group behind the JumpCloud breach left digital footprints behind that allowed researchers to trace their IP addresses.

The breach first emerged last week.

Google-owned security outfit Mandiant has attributed the attack to North Korean group UNC4889, partly because of VPN failures and user errors that exposed the source addresses of traffic.

The group used a series of relay boxes to send traffic over IPsec-encrypted Layer 2 Tunnelling Protocol tunnels to obscure their addresses; alternatively, commercial VPN providers were used.

The commercial providers used included ExpressVPN, NordVPN, TorGuard and others.

Sometimes, Mandiant explained, someone “fumbled”: “DPRK threat actors did not employ this last hop, or mistakenly did not utilise this while conducting actions on operations on the victim's network.”

In addition: “The VPNs used by RGB actors occasionally fail, which reveals the IP addresses of the actor's true origins … Our evidence supports that this was an OPSEC slip up since the connection to the North Korean netblock was short-lived.”

Mandiant said the attacks on JumpCloud used a software supply chain attack.

The attackers compromised JumpCloud and inserted malicious commands into a Ruby script that was part of the company’s commands framework.

The customer Mandiant analysed was infected with the malicious script in a spear phishing attack, and the script then downloaded and executed a stage two payload.

This gave the attacker the chance to install backdoors, with persistence granted via plists.

While JumpCloud has not identified who was affected, Mandiant said the attackers were most interested in cryptocurrency theft.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
jumpcloud mandiant north korea security

Related Articles

  • Malicious AI inputs are creating a new and critical security threat
  • Beware the pitfalls of using a ‘DIY security’ approach
  • AI transforms cyberattacks, but human trust remains the weakest link
  • How severe will ransomware attacks become in 2026?
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Malicious AI inputs are creating a new and critical security threat

Malicious AI inputs are creating a new and critical security threat

Singapore issues advisory for FIs to mitigate quantum computing risks

Singapore issues advisory for FIs to mitigate quantum computing risks

PhilHealth estimates 13 to 20 million members affected by data breach

PhilHealth estimates 13 to 20 million members affected by data breach

Malaysia's Maxis Berhad investigates claims on alleged data breach

Malaysia's Maxis Berhad investigates claims on alleged data breach

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.