A hacking group backed by the North Korean government breached an American IT management company and utilized it as a launching point to attack cryptocurrency companies, according to the company and cybersecurity experts.
In late June, the hackers gained access to JumpCloud, a firm based in Louisville, Colorado. Using this access, they targeted “fewer than 5” of JumpCloud’s clients, as stated in a blog post by the company. While JumpCloud did not disclose the identities of the affected customers, cybersecurity firms CrowdStrike Holdings and Mandiant, who are assisting JumpCloud and one of its clients, respectively, revealed that the hackers are known for focusing on cryptocurrency theft.
Sources familiar with the matter confirmed that the targeted clients were indeed cryptocurrency companies. This incident highlights North Korean cyber spies’ evolving tactics, as they now aim for companies that can provide broader access to multiple downstream victims – a strategy known as a “supply chain attack.”
CrowdStrike identified the hackers as “Labyrinth Chollima”
According to Tom Hegel of US firm SentinelOne, who independently verified the attribution made by Mandiant and CrowdStrike, North Korea appears to be intensifying its cyber activities.
CrowdStrike identified the hackers as “Labyrinth Chollima,” one of several groups believed to operate on behalf of North Korea. Meanwhile, Mandiant attributed the hackers to North Korea’s Reconnaissance General Bureau (RGB), its primary foreign intelligence agency.
Despite evidence, including UN reports, suggesting otherwise, North Korea has consistently denied orchestrating digital currency heists. However, Labyrinth Chollima has been linked to numerous daring and disruptive cyber intrusions, with cryptocurrency theft leading to substantial losses.
Chainalysis, a blockchain analytics firm, estimated that North Korean-linked groups pilfered around $1.7 billion worth of digital currency through multiple hacks.
CrowdStrike’s Adam Meyers warned against underestimating Pyongyang’s hacking squads and predicted that this incident may not be the last North Korean supply chain attack this year.


