JumpCloud hack linked to North Korea after OPSEC mistake

Teilen:

A hacking unit of North Korea’s Reconnaissance General Bureau (RGB) was linked to the JumpCloud breach after the attackers made an operational security (OPSEC) mistake, inadvertently exposing their real-world IP addresses.

The hacking group, tracked as UNC4899 by Mandiant, was previously observed using a combination of commercial VPNs and Operational Relay Boxes (ORBs) using L2TP IPsec tunnels to hide their actual location.

Mandiant says UNC4899 threat actors have used many VPN providers for this purpose in previous campaigns, including ExpressVPN, NordVPN, TorGuard, and others.

While North Korean state hackers are known for using commercial VPN services to mask their IP addresses and actual locations, during the JumpCloud attack, the VPNs they were using failed and exposed their location in Pyongyang while connecting to a victim’s network.

“Mandiant observed the DPRK threat actor UNC4899 connecting directly to an attacker-controlled ORB from their 175.45.178[.]0/24 subnet,” the researchers said.

“Additionally we observed the DPRK threat actor log directly into a Pyongyang IP, from one of their jump boxes. Our evidence supports that this was an OPSEC slip up since the connection to the North Korean netblock was short-lived.”

Apart from this OPSEC oversight, Mandiant security researchers also found attack infrastructure overlapping with previously associated hacks linked to North Korean hackers, further bolstering the attribution of the breach to North Korean hackers.

“We assess with high confidence that UNC4899 is a cryptocurrency-focused group that falls under the RGB. UNC4899’s targeting is selective, and they have been observed gaining access to victim networks through JumpCloud,” Mandiant added.

“Mandiant has observed UNC2970, APT43, and UNC4899 all utilize similar infrastructure.”

North Korean JumpCloud attack flow
North Korean JumpCloud attack flow (Mandiant)

​On Thursday, JumpCloud also confirmed that a North Korean APT group was behind the June breach following attribution from security researchers at SentinelOne and CrowdStrike earlier that day.

Senior Incident Response Consultant Austin Larsen told BleepingComputer that the attackers also hit a downstream victim following their breach of JumpCloud.

Mandiant foresees that additional victims may be currently dealing with the repercussions of this attack.

JumpCloud force-rotated all admin API keys on July 5th, one week after the hacker breached its network via a spear-phishing attack.

While the company has now attributed the attack, it has not yet disclosed the number of impacted customers.

Colorado-based JumpCloud is an operational directory-as-a-service platform that offers single sign-on and multi-factor authentication services to a vast network of over 180,000 organizations spanning more than 160 countries.

 

(c) Sergiu Gatlan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
10:11 am, Mai 19, 2025
Wetter-Symbol 13°C
L: 12° | H: 14°
overcast clouds
Luftfeuchtigkeit: 76 %
Druck: 1021 mb
Wind: 7 mph E
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:02 am
Sonnenuntergang: 8:51 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
12° | 14°°C 0 mm 0% 12 mph 67 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
10° | 22°°C 0 mm 0% 10 mph 67 % 1022 mb 0 mm/h
Mi. Mai 21 10:00 pm
Wetter-Symbol
13° | 21°°C 0.2 mm 20% 9 mph 64 % 1020 mb 0 mm/h
Do. Mai 22 10:00 pm
Wetter-Symbol
11° | 18°°C 0 mm 0% 11 mph 64 % 1023 mb 0 mm/h
Fr. Mai 23 10:00 pm
Wetter-Symbol
7° | 18°°C 0.7 mm 70% 11 mph 77 % 1023 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
14° | 17°°C 0 mm 0% 9 mph 67 % 1021 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
17° | 19°°C 0 mm 0% 12 mph 52 % 1020 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 10 mph 46 % 1020 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
13° | 13°°C 0 mm 0% 7 mph 61 % 1021 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
10° | 10°°C 0 mm 0% 5 mph 66 % 1022 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
10° | 10°°C 0 mm 0% 6 mph 67 % 1021 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 7 mph 63 % 1022 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 7 mph 46 % 1022 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,229.63
-0.74%
Ethereum(ETH)
€2,147.36
-4.66%
Fesseln(USDT)
€0.89
0.00%
XRP(XRP)
€2.06
-3.97%
Solana(SOL)
€144.37
-5.74%
USDC(USDC)
€0.89
0.00%
Dogecoin(DOGE)
€0.193802
-3.44%
Shiba Inu(SHIB)
€0.000013
-5.15%
Pepe(PEPE)
€0.000012
-3.65%
Peanut das Eichhörnchen(PNUT)
€0.282118
-11.82%
Nach oben scrollen