logo

North Korean hackers use EtherHiding to hide malware on the blockchain

ID: 4295bc86-087b-5670-8be3-40f6b2856ef2

STIX ID: report--4295bc86-087b-5670-8be3-40f6b2856ef2

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-10-16

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

North Korean-linked APT UNC5342 has been observed using 'EtherHiding'—embedding payloads in smart contracts on Ethereum and BNB Smart Chain—to stealthily host and deliver a JavaScript downloader (JADESNOW) in recruiter-style social-engineering job interviews. The downloader retrieves an in-memory JavaScript version of InvisibleFerret and credential-stealing components that target browser-stored passwords, payment cards, and cryptocurrency wallets (MetaMask, Phantom); attackers exploit read-only blockchain calls for stealth, update contracts cheaply and across multiple chains, complicating detection and takedown.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.