North Korean EtherHiding Campaign Targets Crypto Wallets and Developer Credentials
ID: 539db125-0f23-500e-90fb-ceb4b613a9d6
STIX ID: report--539db125-0f23-500e-90fb-ceb4b613a9d6
Feed Name: cybersecurityNews.com
AllSecure researchers identified a North Korean-linked campaign that uses fake macOS update pages delivered via malvertising to trick victims into pasting Terminal commands that install a Node.js remote access trojan and infostealer. The malware uses Ethereum smart contracts (EtherHiding) to retrieve live C2 configuration, deploys a malicious Chrome MV3 extension disguised as "Google Drive Offline," collects credentials and crypto wallets, and establishes persistence; researchers observed substantial cryptocurrency movement tied to the operation and provided IoCs and containment guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
