BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

North Korean Hackers Use EtherHiding for Malware, Crypto Theft

North Korean-Linked Hackers Use EtherHiding to Spread Malware and Steal Cryptocurrency via Blockchain Smart Contracts Targeting Developers

  • A North Korean-linked Hacking group has used the EtherHiding method to spread Malware and steal cryptocurrency.
  • The campaign targets developers on LinkedIn, then uses Telegram or Discord to deliver malicious code.
  • EtherHiding stores harmful code inside blockchain smart contracts, making it hard to remove or trace.
  • The attack affects Windows, macOS, and Linux with multiple malware families, including backdoors and data stealers.
  • This marks the first time a state-sponsored actor has employed EtherHiding, highlighting a shift in cyberattack techniques.

A threat group connected to North Korea has employed the EtherHiding technique to distribute malware and steal cryptocurrency. This activity, observed by the Google Threat Intelligence Group (GTIG), began in February 2025. The group, known in different security communities by names such as UNC5342 and Famous Chollima, targets developers through LinkedIn before moving conversations to platforms like Telegram or Discord to deploy malicious code.

- Advertisement -

The campaign, called Contagious Interview, aims to gain unauthorized access to developers’ devices, exfiltrate sensitive information, and illegally acquire cryptocurrency assets. EtherHiding works by embedding harmful code in blockchain smart contracts on networks like Ethereum or BNB Smart Chain. This lets the attackers use the blockchain as a decentralized dead drop resolver, a way to exchange data that is resistant to takedown or tracing efforts.

Google noted that EtherHiding makes use of the blockchain’s pseudonymous transactions to hide who deploys the contracts. The attackers can also update the malware at any time, paying an average blockchain fee of about $1.37. Robert Wallace, a consulting leader at Mandiant, Google Cloud, said in a statement, “This development signals an escalation in the threat landscape, as nation-state threat actors are now utilizing new techniques to distribute malware that is resistant to law enforcement take-downs and can be easily modified for new campaigns.”

Following social engineering steps, the infection targets Windows, macOS, and Linux using several malware types: an initial downloader disguised as npm packages, BeaverTail (a JavaScript stealer that collects cryptocurrency wallets and credentials), JADESNOW (a downloader using EtherHiding), and InvisibleFerret (a Python backdoor enabling remote access and persistent data theft). The backdoor specifically targets wallets like MetaMask and Phantom and password managers such as 1Password.

Google described EtherHiding as a move toward advanced bulletproof Hosting, where blockchain features are exploited for malicious purposes. This underscores ongoing cyber threat evolution as attackers adopt new technologies for their activities.

- Advertisement -

For more details, see the public report from the Google Threat Intelligence Group here.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

ShapedPlugin WordPress Backdoor in Supply Chain

Pro versions of three ShapedPlugin WordPress extensions were backdoored after attackers hijacked the official...

Saylor’s Strategy Says Its Stock Differs From Terra’s

Analyst Mark Palmer from Benchmark-StoneX rejects comparisons between Strategy’s volatile STRC and the collapsed...

Coinbase Launches AI Pre-IPO Futures for OpenAI & Anthropic

Coinbase has launched pre-IPO perpetual futures for AI giants OpenAI and Anthropic, expanding its...

NY Atty Seeks to Unmask ‘Noah Doe’ Claiming $245B in BTC

An anonymous entity seeks legal title to ~3.8 million dormant BTC, including Satoshi's, valued...

Andrew Cuomo to co-chair ICE-OKX digital assets venture

OKX and Intercontinental Exchange (ICE), parent of the NYSE, announced a joint venture co-chaired...

Must Read

14 Ways On How to Make Money with Cryptocurrency

Many people want to make money with cryptocurrency because they have heard the success stories of people who became millionaires from zero.If you...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading