By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: North Korean Hackers Use EtherHiding to Hide Malware Inside Blockchain Smart Contracts
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > North Korean Hackers Use EtherHiding to Hide Malware Inside Blockchain Smart Contracts
Computing

North Korean Hackers Use EtherHiding to Hide Malware Inside Blockchain Smart Contracts

News Room
Last updated: 2025/10/16 at 11:47 AM
News Room Published 16 October 2025
Share
North Korean Hackers Use EtherHiding to Hide Malware Inside Blockchain Smart Contracts
SHARE

Oct 16, 2025Ravie LakshmananMalware / Blockchain

A threat actor with ties to the Democratic People’s Republic of Korea (aka North Korea) has been observed leveraging the EtherHiding technique to distribute malware and enable cryptocurrency theft, marking the first time a state-sponsored hacking group has embraced the method.

The activity has been attributed by Google Threat Intelligence Group (GTIG) to a threat cluster it tracks as UNC5342, which is also known as CL-STA-0240 (Palo Alto Networks Unit 42), DeceptiveDevelopment (ESET), DEV#POPPER (Securonix), Famous Chollima (CrowdStrike), Gwisin Gang (DTEX), Tenacious Pungsan (Datadog), and Void Dokkaebi (Trend Micro).

The attack wave is part of a long-running campaign codenamed Contagious Interview, wherein the attackers approach potential targets on LinkedIn by posing as recruiters or hiring managers, and trick them into running malicious code under the pretext of a job assessment after shifting the conversation to Telegram or Discord.

The end goal of these efforts is to gain unauthorized access to developers’ machines, steal sensitive data, and siphon cryptocurrency assets – consistent with North Korea’s twin pursuit of cyber espionage and financial gain.

Google said it has observed UNC5342 incorporating EtherHiding – a stealthy approach that involves embedding nefarious code within a smart contract on a public blockchain like BNB Smart Chain (BSC) or Ethereum – since February 2025. In doing so, the attack turns the blockchain into a decentralized dead drop resolver that’s resilient to takedown efforts.

CIS Build Kits

Besides resilience, EtherHiding also abuses the pseudonymous nature of blockchain transactions to make it harder to trace who has deployed the smart contract. Complicating matters further, the technique is also flexible in that it allows the attacker who is in control of the smart contract to update the malicious payload at any time (albeit costing an average of $1.37 in gas fees), thereby opening the door to a wide spectrum of threats.

“This development signals an escalation in the threat landscape, as nation-state threat actors are now utilizing new techniques to distribute malware that is resistant to law enforcement take-downs and can be easily modified for new campaigns,” Robert Wallace, consulting leader at Mandiant, Google Cloud, said in a statement shared with The Hacker News.

The infection chain triggered following the social engineering attack is a multi-stage process that’s capable of targeting Windows, macOS, and Linux systems with three different malware families –

  • An initial downloader that manifests in the form of npm packages
  • BeaverTail, a JavaScript stealer that’s responsible for exfiltrating sensitive information, such as cryptocurrency wallets, browser extension data, and credentials
  • JADESNOW, a JavaScript downloader that uses EtherHiding to fetch InvisibleFerret
  • InvisibleFerret, a Python backdoor deployed against high-value targets to allow remote control of the compromised host, as well as long-term data theft by targeting MetaMask and Phantom wallets, as well as credentials from password managers like 1Password

“EtherHiding represents a shift toward next-generation bulletproof hosting, where the inherent features of blockchain technology are repurposed for malicious ends,” Google said. “This technique underscores the continuous evolution of cyber threats as attackers adapt and leverage new technologies to their advantage.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article AWS Launches Amazon Quick Suite, an Agentic AI Workspace AWS Launches Amazon Quick Suite, an Agentic AI Workspace
Next Article Deals: Amazon slashes 0 off M4 Pro MacBook Pro, now ,749 Deals: Amazon slashes $250 off M4 Pro MacBook Pro, now $1,749
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Tribit StormBox Mini+ Review: The Best-Sounding  Bluetooth Speaker We’ve Tested
Tribit StormBox Mini+ Review: The Best-Sounding $40 Bluetooth Speaker We’ve Tested
News
Google might soon limit this popular Pixel Watch feature when you choose extra security
Google might soon limit this popular Pixel Watch feature when you choose extra security
News
Level Lock Pro: Hands on review with Matter, Thread, and more
Level Lock Pro: Hands on review with Matter, Thread, and more
News
5 Best Low-Cost Options Trading Platforms in the UAE
5 Best Low-Cost Options Trading Platforms in the UAE
Gadget

You Might also Like

👨🏿‍🚀 Daily – Mobile money turf war |
Computing

👨🏿‍🚀 Daily – Mobile money turf war |

3 Min Read
Redmi 14C unpacked: Full specs, price, and value in Nigeria
Computing

Redmi 14C unpacked: Full specs, price, and value in Nigeria

12 Min Read
Multiple Chinese cities pause trade-in subsidies, sparking confusion amid 618 sales rush · TechNode
Computing

Multiple Chinese cities pause trade-in subsidies, sparking confusion amid 618 sales rush · TechNode

1 Min Read
MuddyWater Deploys UDPGangster Backdoor in Targeted Turkey-Israel-Azerbaijan Campaign
Computing

MuddyWater Deploys UDPGangster Backdoor in Targeted Turkey-Israel-Azerbaijan Campaign

4 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?