According to reports from security researchers at SentinelOne , CrowdStrike , and Mandiant , North Korean hackers Lazarus are behind the recent hack of software company JumpCloud.

In a report published Thursday, Tom Hegel , a senior researcher at SentinelOne, linked the North Korean threat group to the JumpCloud attack, based on multiple indicators of compromise that the company itself shared in a recent report.
Cybersecurity firm CrowdStrike also identified Labyrinth Chollima (whose activity overlaps with that of the Lazarus Group, ZINC, and Black Artemis) as the group behind the breach. CrowdStrike had partnered with JumpCloud to assist in the investigation.
See also: GitHub: Lazarus hackers target devs with malicious projects
“One of their primary goals was to generate revenue for the regime. I don’t think this will be the last attack we see from North Korea this year,” CrowdStrike executive Adam Meyers told Reuters.
Finally, Mandiant also said that the attack was carried out by North Korean hackers, who are known for targeting crypto organizations.
“This is a financially motivated threat actor that we have seen increasingly target the cryptocurrency industry and various platforms blockchain,” said Austin Larsen of Mandiant.
Larsen also said that the attackers have already hit one victim after the JumpCloud breach, with Mandiant expecting that there are other victims currently dealing with the consequences of the attack.
The Lazarus hackers have been active since at least 2009 and are known for attacks against high-profile targets worldwide. Their victims include banks, government agencies, and media organizations.
See also: Gamaredon hackers steal data in less than an hour after breach
JumpCloud confirms hack was carried out by North Korean hackers
On June 27, JumpCloud discovered an incident in which “an advanced nation-state-sponsored threat actor” compromised systems through a spear-phishing attack. While there was no immediate indication of the impact of the attack on customers, JumpCloud proactively rotated credentials and rebuilt the compromised infrastructure.
During the investigation, on July 5, JumpCloud detected “unusual activity in the commands framework for a small set of customers.” Working with experts and law enforcement, it also analyzed logs for signs of malicious activity and force-rotated all admin API keys.

On July 12, JumpCloud shared details about the incident and published indicators of compromise (IOCs) to help partners protect networks from attacks.
After confirming that a North Korean hacking group was behind the attack, the company also said that fewer than 5 JumpCloud customers and fewer than 10 devices were affected. All affected customers have been notified directly.
See also: APT29 hackers lure diplomats with car ads – Greek diplomats also at risk
“After identifying the incident, we immediately took action to mitigate the threat, secure the network, communicate with customers , and notify law enforcement,” JumpCloud spokesperson Josie Judy told TechCrunch.
JumpCloud is a very popular software company and provides multi-factor authentication and login services to more than 180,000 organizationsin more than 160 countries. As for the Lazarus Group, which is likely behind the JumpCloud hack, it represents one of the biggest threats to cybersecurity. These hackers have targeted a wide range of organizations and individuals with their advanced hacking capabilities and continue to evolve their tactics. But by following good cybersecurity, you can protect yourself and your organization from Lazarus Group attacks. Stay alert, stay informed, and be prepared to respond quickly in the event of an attack.
Source: www.bleepingcomputer.com
