Sunday, October 19, 2025
55.9 F
New York

North Korean hackers found hiding crypto-stealing malware with Blockchain

North Korean flag with a hooded hacker
(Image credit: Shutterstock)

  • UNC5342 uses blockchain smart contracts to deliver crypto-stealing malware via EtherHiding
  • Fake jobs and coding challenges lure developers into triggering the JadeSnow loader and backdoor
  • Blockchain’s immutability makes malware hosting resilient

North Korean state-sponsored threat actors are now using public blockchains to host malicious code and deploy malware on target endpoints.

This is according to Google’s Threat Intelligence Group (GTIG), who said they observed UNC5342 using Ethereum and BNB to host droppers and ultimately deploy cryptocurrency-stealing malware against software and blockchain developers.

The technique is called EtherHiding. Instead of sending a malicious file directly to the victim (or otherwise tricking them into downloading it), they encode parts of the malware into blockchain transactions and smart contracts.

Evolution of bulletproof hosting

The smart contract itself doesn’t execute malware automatically on someone’s computer, but it can deliver instructions or code when a user interacts with it (when they click a link, run a script, or connect a crypto wallet).

The blockchain is a great place to store and distribute malware since it is public, immutable, and almost impossible to tamper.

“This represents a shift toward next-generation bulletproof hosting,” Google said, stressing that the blockchain’s resilient nature is what makes it so enticing for cybercrooks.

From February, UNC5342 was observed creating fake jobs and coding challenges, tricking developers and others working in the Web3 space to download different files. These files connect to the blockchain and retrieve the code which, in turn, installs the JadeSnow loader. This loader drops the InvisibleFerret backdoor, which was already observed used in cryptocurrency thefts.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

This is not the first time we’re seeing blockchain being used to deliver malware. The technique has been in use since 2023, and in the same report, Google also mentioned a financially motivated actor UNC5142 using the same technique.

This group was seen compromising WordPress sites to host malicious JavaScript code that connected to the blockchain. More than 14,000 infected sites were found so far.

North Korea is known for targeting the crypto industry and using the stolen funds to finance its weapons program and state apparatus.

Via The Record


Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

You might also like

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Hot this week

Gaza ceasefire: US says Hamas is planning ‘imminent’ attack on civilians

US warns of 'imminent' breach of Gaza ceasefire with...

Terrassa: Catalonian town bans black cat adoptions during Halloween

The Spanish town of Terrassa in north-eastern Catalonia has...

Betfred says all its shops may close if Reeves hikes gambling tax

Simon JackBusiness editor and Josh MartinBusiness reporter All 1,287 Betfred shops...

‘I saw my Gaza homeland rebuilt before but this time’s different’

'I'm 89 and I saw my homeland rebuilt before...

‘Bali-fication’ comes for Lombok, a laidback surfers island

'I miss the past, but we like the money':...

Topics

Terrassa: Catalonian town bans black cat adoptions during Halloween

The Spanish town of Terrassa in north-eastern Catalonia has...

Betfred says all its shops may close if Reeves hikes gambling tax

Simon JackBusiness editor and Josh MartinBusiness reporter All 1,287 Betfred shops...

No Kings: Thousands attend anti-Trump protest across the US

Huge crowds gathered to protest against President Donald Trump's...

Limp Bizkit bassist Sam Rivers dies aged 48

Stefan Hoederath/Redferns via Getty Images Sam Rivers and Fred Durst...

Related Articles

Popular Categories