TLDR North Korean hackers are utilizing blockchain technology to develop decentralized command systems. Fake job offers are a common tactic for North Korean cyberattacks. Malware like BeaverTail and OtterCookie is used for credential theft. EtherHiding malware hides payloads on public blockchains for stealth. North Korea-linked hackers are increasing their global cyberattacks using new decentralized and [...] The post North Korean Hackers Expand Global Cyberattacks Using Blockchain Tools appeared first on CoinCentral.TLDR North Korean hackers are utilizing blockchain technology to develop decentralized command systems. Fake job offers are a common tactic for North Korean cyberattacks. Malware like BeaverTail and OtterCookie is used for credential theft. EtherHiding malware hides payloads on public blockchains for stealth. North Korea-linked hackers are increasing their global cyberattacks using new decentralized and [...] The post North Korean Hackers Expand Global Cyberattacks Using Blockchain Tools appeared first on CoinCentral.

North Korean Hackers Expand Global Cyberattacks Using Blockchain Tools

TLDR

  • North Korean hackers are utilizing blockchain technology to develop decentralized command systems.
  • Fake job offers are a common tactic for North Korean cyberattacks.
  • Malware like BeaverTail and OtterCookie is used for credential theft.
  • EtherHiding malware hides payloads on public blockchains for stealth.

North Korea-linked hackers are increasing their global cyberattacks using new decentralized and evasive malware tools, according to recent reports from Cisco Talos and Google’s Threat Intelligence Group (GTIG). These campaigns target individuals and companies through fake job recruitment schemes, aiming to steal cryptocurrency, access networks, and evade detection. Researchers warn that the use of blockchain-based command systems is making these operations harder to disrupt.

Expanding Cyber Operations Using Advanced Malware

Cisco Talos has identified a North Korean threat group known as Famous Chollima, which continues to evolve its tactics and tools. The group has been observed using two related malware families named BeaverTail and OtterCookie, both developed to steal credentials and collect sensitive data. These updated variants now share functions that improve communication and efficiency during attacks.

In one case investigated by Cisco Talos, a Sri Lankan organization was indirectly affected when a job seeker was deceived into installing a malicious program as part of a fake technical test. The malware included modules for recording keystrokes and taking screenshots. The collected information was then sent to remote servers controlled by the attackers. Researchers said that this method shows how individuals can be compromised even when organizations are not direct targets.

Blockchain as a Decentralized Command System

Google’s Threat Intelligence Group reported that a North Korean-linked actor, known as UNC5342, has deployed a new malware called EtherHiding. This malware hides malicious JavaScript payloads on public blockchains. By using this approach, attackers build a decentralized command and control (C2) system that is difficult for authorities to remove.

According to GTIG, EtherHiding allows attackers to modify malware behavior remotely without relying on traditional servers. This technique reduces the chances of disruption since blockchain data cannot be easily taken down. Google researchers connected this operation to a broader campaign named Contagious Interview, where fake job offers were used to infect victims. The findings reveal that North Korean groups are integrating decentralized technology to maintain persistence across multiple operations.

Fake Recruitment Campaigns as a Primary Entry Point

Both Cisco and Google observed that these cyber operations often start with fraudulent job postings aimed at professionals in the cryptocurrency and cybersecurity industries. Victims are contacted with supposed interview offers and asked to complete fake assessments that include files embedded with malware.

The infections involve a mix of malware families such as JadeSnow, BeaverTail, and InvisibleFerret, which together enable attackers to steal credentials, deploy ransomware, and gain deeper access into systems. Researchers believe the campaigns seek both financial gain and long-term access to corporate environments for espionage and future exploitation.

Defensive Measures and Ongoing Threats

Cisco Talos and Google have released indicators of compromise (IOCs) to help organizations detect related malicious activity. These indicators include technical markers that security teams can use to monitor and block suspicious behavior linked to these campaigns.

Analysts say that the combination of social engineering and blockchain-based tools is creating new challenges for cybersecurity defense. Since public blockchains cannot be easily controlled or shut down, they are becoming a preferred infrastructure for threat actors seeking to maintain access and conceal their operations.

Researchers from both companies continue to track these campaigns and share findings with the global cybersecurity community. They recommend that organizations verify job offers carefully, restrict file downloads during hiring processes, and update monitoring systems to detect evolving malware families like BeaverTail, OtterCookie, and EtherHiding.

The post North Korean Hackers Expand Global Cyberattacks Using Blockchain Tools appeared first on CoinCentral.

Market Opportunity
Wink Logo
Wink Price(LIKE)
$0.003907
$0.003907$0.003907
+19.29%
USD
Wink (LIKE) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Fed Decides On Interest Rates Today—Here’s What To Watch For

Fed Decides On Interest Rates Today—Here’s What To Watch For

The post Fed Decides On Interest Rates Today—Here’s What To Watch For appeared on BitcoinEthereumNews.com. Topline The Federal Reserve on Wednesday will conclude a two-day policymaking meeting and release a decision on whether to lower interest rates—following months of pressure and criticism from President Donald Trump—and potentially signal whether additional cuts are on the way. President Donald Trump has urged the central bank to “CUT INTEREST RATES, NOW, AND BIGGER” than they might plan to. Getty Images Key Facts The central bank is poised to cut interest rates by at least a quarter-point, down from the 4.25% to 4.5% range where they have been held since December to between 4% and 4.25%, as Wall Street has placed 100% odds of a rate cut, according to CME’s FedWatch, with higher odds (94%) on a quarter-point cut than a half-point (6%) reduction. Fed governors Christopher Waller and Michelle Bowman, both Trump appointees, voted in July for a quarter-point reduction to rates, and they may dissent again in favor of a large cut alongside Stephen Miran, Trump’s Council of Economic Advisers’ chair, who was sworn in at the meeting’s start on Tuesday. It’s unclear whether other policymakers, including Kansas City Fed President Jeffrey Schmid and St. Louis Fed President Alberto Musalem, will favor larger cuts or opt for no reduction. Fed Chair Jerome Powell said in his Jackson Hole, Wyoming, address last month the central bank would likely consider a looser monetary policy, noting the “shifting balance of risks” on the U.S. economy “may warrant adjusting our policy stance.” David Mericle, an economist for Goldman Sachs, wrote in a note the “key question” for the Fed’s meeting is whether policymakers signal “this is likely the first in a series of consecutive cuts” as the central bank is anticipated to “acknowledge the softening in the labor market,” though they may not “nod to an October cut.” Mericle said he…
Share
BitcoinEthereumNews2025/09/18 00:23
Sonami Token Presale Launches With 53% Staking Rewards, Powering a Solana Layer-Two Network Vision

Sonami Token Presale Launches With 53% Staking Rewards, Powering a Solana Layer-Two Network Vision

The post Sonami Token Presale Launches With 53% Staking Rewards, Powering a Solana Layer-Two Network Vision appeared on BitcoinEthereumNews.com. Sonami Token Presale
Share
BitcoinEthereumNews2026/01/21 16:05
Will Intel stock keep soaring as Q4 earnings approach?

Will Intel stock keep soaring as Q4 earnings approach?

The post Will Intel stock keep soaring as Q4 earnings approach? appeared on BitcoinEthereumNews.com. Even though Intel (INTC) was once the world’s largest semiconductor
Share
BitcoinEthereumNews2026/01/21 16:24