Tech Wavo
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock
Tech Wavo
No Result
View All Result

North Korean hackers found hiding crypto-stealing malware with Blockchain

Tech Wavo by Tech Wavo
October 17, 2025
in Computers
0




  • UNC5342 uses blockchain smart contracts to deliver crypto-stealing malware via EtherHiding
  • Fake jobs and coding challenges lure developers into triggering the JadeSnow loader and backdoor
  • Blockchain’s immutability makes malware hosting resilient

North Korean state-sponsored threat actors are now using public blockchains to host malicious code and deploy malware on target endpoints.

This is according to Google’s Threat Intelligence Group (GTIG), who said they observed UNC5342 using Ethereum and BNB to host droppers and ultimately deploy cryptocurrency-stealing malware against software and blockchain developers.

The technique is called EtherHiding. Instead of sending a malicious file directly to the victim (or otherwise tricking them into downloading it), they encode parts of the malware into blockchain transactions and smart contracts.


You may like

Evolution of bulletproof hosting

The smart contract itself doesn’t execute malware automatically on someone’s computer, but it can deliver instructions or code when a user interacts with it (when they click a link, run a script, or connect a crypto wallet).

The blockchain is a great place to store and distribute malware since it is public, immutable, and almost impossible to tamper.

“This represents a shift toward next-generation bulletproof hosting,” Google said, stressing that the blockchain’s resilient nature is what makes it so enticing for cybercrooks.

From February, UNC5342 was observed creating fake jobs and coding challenges, tricking developers and others working in the Web3 space to download different files. These files connect to the blockchain and retrieve the code which, in turn, installs the JadeSnow loader. This loader drops the InvisibleFerret backdoor, which was already observed used in cryptocurrency thefts.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

This is not the first time we’re seeing blockchain being used to deliver malware. The technique has been in use since 2023, and in the same report, Google also mentioned a financially motivated actor UNC5142 using the same technique.

This group was seen compromising WordPress sites to host malicious JavaScript code that connected to the blockchain. More than 14,000 infected sites were found so far.

North Korea is known for targeting the crypto industry and using the stolen funds to finance its weapons program and state apparatus.

Via The Record


Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

You might also like

Previous Post

WhatsApp will test a monthly cap on messages ignored by recipients

Next Post

5 Great Cocktail and Drink Apps

Next Post
5 Great Cocktail and Drink Apps

5 Great Cocktail and Drink Apps

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Interlock ransomware just keeps getting more powerful – here’s how to stay safe

by Tech Wavo
October 17, 2025
0
Major data breach at dealership software firm exposes 766,000 clients – here’s what we know
Computers

Interlock ransomware reached operational maturity, now targeting healthcare, government, and manufacturing sectorsIt supports multi-platform attacks, cloud-based C2, full lifecycle automationForescout...

Read more

Ring’s latest partnership allows police to access camera footage through Flock

by Tech Wavo
October 17, 2025
0
Ring’s latest partnership allows police to access camera footage through Flock
Computers

Amazon's Ring brand is entering into a new partnership with surveillance company Flock Safety to make it possible for law...

Read more

Android Auto is axing support for some older devices – check if yours is affected now

by Tech Wavo
October 17, 2025
0
Android Auto is axing support for some older devices – check if yours is affected now
Computers

Google has pushed the Android Auto beta 15.5 to some devicesThose running Android 8 will soon not be supportedOlder devices...

Read more

Chunky frames with impressive abilities

by Tech Wavo
October 17, 2025
0
Chunky frames with impressive abilities
Computers

I've been wearing the $800 Meta Ray-Ban Display glasses daily for ten days and I'm still a bit conflicted. On...

Read more

Site links

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use
  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use

No Result
View All Result
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock