North Korean hackers are deploying new malware to steal cryptocurrency using EtherHiding without detection, which symbolizes the dawn of blockchain-based cyberattacks. According to cybersecurity teams, UNC5342, a state-sponsored group, is the first nation-state that uses EtherHiding for malware attacks and crypto theft.   According to the Google Threat Intelligence Group (GTIG), which was reported by The […] The post Crypto Hack News: North Korean Hackers Exploit EtherHiding for Crypto Thefts appeared first on Live Bitcoin News.North Korean hackers are deploying new malware to steal cryptocurrency using EtherHiding without detection, which symbolizes the dawn of blockchain-based cyberattacks. According to cybersecurity teams, UNC5342, a state-sponsored group, is the first nation-state that uses EtherHiding for malware attacks and crypto theft.   According to the Google Threat Intelligence Group (GTIG), which was reported by The […] The post Crypto Hack News: North Korean Hackers Exploit EtherHiding for Crypto Thefts appeared first on Live Bitcoin News.

Crypto Hack News: North Korean Hackers Exploit EtherHiding for Crypto Thefts

2025/10/18 08:00
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

North Korean hackers are deploying new malware to steal cryptocurrency using EtherHiding without detection, which symbolizes the dawn of blockchain-based cyberattacks.

According to cybersecurity teams, UNC5342, a state-sponsored group, is the first nation-state that uses EtherHiding for malware attacks and crypto theft.  

According to the Google Threat Intelligence Group (GTIG), which was reported by The Hacker News, this method incorporates malicious code in the form of smart contracts on blockchains such as Ethereum and BNB Smart Chain (BSC).  

By turning the blockchain into a decentralized “dead drop”, the attackers make takedowns cumbersome, and it is not clear where the attack originated.  

It also gives attackers the ability to update smart contract malware at will while experiencing dynamic control with a low gas fee update cost.

Sneaky Social Engineering Targets Developers via LinkedIn

Dubbed the “Contagious Interview” hacking campaign, UNC5342 is a sophisticated social engineering campaign.  

Attackers create LinkedIn profiles that imitate recruiters and lure their targets to Telegram or Discord channels. There, they persuade the victims to run malicious code disguised as job tests.

The ultimate objective is to gain unauthorized access to developers’ devices, steal sensitive information, and seize crypto assets. These actions align with North Korea’s dual goals of cyber espionage and financial gain.

Complex Multi-Stage Malware Chain

The infection chain is for Windows, macOS, and Linux. First, it uses a downloader that appears as a JavaScript that looks like an npm package.  

Subsequent stages are BeaverTail, which is used to steal cryptocurrency wallets, and JADESNOW, which can interact with Ethereum smart contracts to download InvisibleFerret.  

InvisibleFerret, a JavaScript version of a Python backdoor, allows long-term data stealing and remote management of infected computers.  

The malware additionally has installed a portable Python interpreter to run additional credential stealers associated with Ethereum addresses.

A New Era of Blockchain-Enabled Cyber Threats

Cybersecurity researchers say this is a serious increase in cyber threats. Law enforcement takedowns are hampered by the “bulletproof” nature of the host layer, which is based on blockchain technology.  

According to Google’s security team, the attackers’ use of multiple blockchains in EtherHiding is significant. It shows how cybercriminals adapt by exploiting emerging technologies for their benefit.

The insight reveals that state-backed actors are exploiting decentralized technologies for crypto theft and espionage. This marks a troubling evolution in global cyber threats.

The post Crypto Hack News: North Korean Hackers Exploit EtherHiding for Crypto Thefts appeared first on Live Bitcoin News.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Fed rate decision September 2025

Fed rate decision September 2025

The post Fed rate decision September 2025 appeared on BitcoinEthereumNews.com. WASHINGTON – The Federal Reserve on Wednesday approved a widely anticipated rate cut and signaled that two more are on the way before the end of the year as concerns intensified over the U.S. labor market. In an 11-to-1 vote signaling less dissent than Wall Street had anticipated, the Federal Open Market Committee lowered its benchmark overnight lending rate by a quarter percentage point. The decision puts the overnight funds rate in a range between 4.00%-4.25%. Newly-installed Governor Stephen Miran was the only policymaker voting against the quarter-point move, instead advocating for a half-point cut. Governors Michelle Bowman and Christopher Waller, looked at for possible additional dissents, both voted for the 25-basis point reduction. All were appointed by President Donald Trump, who has badgered the Fed all summer to cut not merely in its traditional quarter-point moves but to lower the fed funds rate quickly and aggressively. In the post-meeting statement, the committee again characterized economic activity as having “moderated” but added language saying that “job gains have slowed” and noted that inflation “has moved up and remains somewhat elevated.” Lower job growth and higher inflation are in conflict with the Fed’s twin goals of stable prices and full employment.  “Uncertainty about the economic outlook remains elevated” the Fed statement said. “The Committee is attentive to the risks to both sides of its dual mandate and judges that downside risks to employment have risen.” Markets showed mixed reaction to the developments, with the Dow Jones Industrial Average up more than 300 points but the S&P 500 and Nasdaq Composite posting losses. Treasury yields were modestly lower. At his post-meeting news conference, Fed Chair Jerome Powell echoed the concerns about the labor market. “The marked slowing in both the supply of and demand for workers is unusual in this less dynamic…
Share
BitcoinEthereumNews2025/09/18 02:44
Ripple Announces Major Expansion in Payment Solution Ripple Payments

Ripple Announces Major Expansion in Payment Solution Ripple Payments

Ripple, the company behind XRP, has announced new expansions to its payments solution. Here are the details. Continue Reading: Ripple Announces Major Expansion
Share
Bitcoinsistemi2026/03/04 13:38
The Role of Reference Points in Achieving Equilibrium Efficiency in Fair and Socially Just Economies

The Role of Reference Points in Achieving Equilibrium Efficiency in Fair and Socially Just Economies

This article explores how a simple change in the reference point can achieve a Pareto-efficient equilibrium in both free and fair economies and those with social justice.
Share
Hackernoon2025/09/17 22:30