securityonline.info 10/20/2025, 12:55:37 AM · via preferred

North Korea’s UNC5342 APT Uses EtherHiding to Store Malware in Blockchain Smart Contracts for Stealthy C2

North Korea’s UNC5342 APT Uses EtherHiding to Store Malware in Blockchain Smart Contracts for Stealthy C2

GOOGLE Threat Intelligence Group (GTIG) has uncovered a new campaign by the North Korean threat actor UNC5342, marking the first known instance of a nation-state actor using EtherHiding to store malware in blockchain smart contracts for stealthy C2 on BNB Smart Chain and Ethereum. EtherHiding embeds malicious JavaScript payloads directly inside smart contracts, allowing the blockchain itself to act as a decentralised, persistent command-and-control server, resistant to takedowns.

According to GTIG, UNC5342’s Contagious Interview social engineering campaign leads victims to download code samples containing the JADESNOW downloader, which then fetches further payloads from smart contracts and deploys backdoors such as INVISIBLEFERRET.

The final stage includes a Python-based backdoor capable of remote command execution and exfiltration of files, browser data, and cryptocurrency wallets, with some instances contacting attacker-controlled servers via MySQL port 3306 and even using a portable Python interpreter to grab credentials for MetaMask, Phantom, Chrome and Edge.

GTIG notes the campaign serves espionage and financial gain objectives, and that attackers can update payloads by sending new blockchain transactions for less than $2 in gas fees per update. Because UNC5342 relies on centralised API providers like Binplorer, Etherscan and Ethplorer rather than operating its own nodes, defenders have an interception point to monitor or suspend malicious activity, according to GTIG.

View full article

Article by CyberSIXT