logo

DPRK Adopts EtherHiding: Nation-State Malware Hiding on Blockchains

ID: 7c612357-3909-5bdd-af55-ef04bbb605cf

STIX ID: report--7c612357-3909-5bdd-af55-ef04bbb605cf

Feed Name: Threat Intelligence

Threat Score
86/100

Date Published: 2025-10-16

Date Updated: 2026-04-27

Author: Mandiant

...
...

**Executive Summary:** A North Korea-linked campaign (UNC5342) uses convincing fake recruiters and fabricated companies to lure software developers into downloading malicious code during technical assessments; the attack chain leverages JavaScript downloaders (JADESNOW) and EtherHiding via smart contracts on Ethereum/BNB to fetch second- and third-stage payloads (BEAVERTAIL, INVISIBLEFERRET), enabling cryptocurrency theft, credential and wallet exfiltration, and persistent backdoors for long-term espionage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.