A threat actor with ties to the Democratic People's Republic of Korea has been observed leveraging the EtherHiding to distribute malware and support cryptocurrency theft, marking the first time a state-backed hacking group has adopted this method.
See also: Treasury imposes sanctions on North Korea

The activity has been attributed by the Google Threat Intelligence Group (GTIG) to a threat group it tracks as UNC5342, also known as CL-STA-0240 (Palo Alto Networks Unit 42), DeceptiveDevelopment (ESET), DEV#POPPER (Securonix), Famous Chollima (CrowdStrike), Gwisin Gang (DTEX), Tenacious Pungsan (Datadog), and Void Dokkaebi (Trend Micro).
The wave of attacks is part of a long-running campaign codenamed Contagious Interview, where attackers approach potential targets on LinkedIn pretending to be hiring managers, tricking them into executing malicious code under the guise of a job evaluation after transferring the conversation to Telegram or Discord.
The ultimate goal of these efforts is to gain unauthorized access to programmers' computers, steal sensitive data, and extract cryptocurrency, in line with North Korea's dual pursuit of cyberespionage and financial gain.
Google reported that it has observed UNC5342 incorporating EtherHiding—a stealth approach that involves embedding malicious code within a smart contract on a public blockchain such as BNB Smart Chain (BSC) or Ethereum—since February 2025. This attack turns the blockchain into a decentralized deadlock solver that is resistant to takedown attempts.
See also: North Korean hackers attack Ukrainian government agencies

In addition to resilience, EtherHiding also takes advantage of the pseudonymous nature of blockchain transactions to make it difficult to trace who developed the smart contract. The technique is flexible, allowing an attacker controlling the smart contract to update the malicious payload at any time, thus opening the door to a wide range of threats.
“This development marks an escalation in the threat landscape, as state-sponsored malicious actors are now using new techniques to distribute malware that is resistant to law enforcement takedowns and can be easily modified for new campaigns,” said Robert Wallace, consulting leader at Mandiant, Google Cloud.
The infection chain triggered after the social engineering attack is a multi-stage process capable of targeting Windows, macOS, and Linux systems with three different malware families:
1. An initial downloader that appears in the form of npm packages.
2. BeaverTail, a JavaScript stealer responsible for extracting sensitive information such as cryptocurrency wallets, browser extension data, and credentials.
3. JADESNOW, a JavaScript downloader that uses EtherHiding to retrieve InvisibleFerret.
See also: Hacker tried to breach Kraken platform via job application

InvisibleFerret is a Python backdoor deployed against high-value targets to allow remote control of the compromised computer, as well as long-term data theft by targeting MetaMask and Phantom, as well as credentials from password managers like 1Password.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
