North Korean hackers have adopted the 'EtherHiding' technique that leverages smart contracts to host and deliver malware in social engineering campaigns that steal cryptocurrency. Google Threat Intelligence Group (GTIG) says that a DPRK nation state threat actor, tracked internally as UNC5342, has been employing EtherHiding since February in Contagious Interview operations. The researchers note that this is the first time they saw a state-backed hacker group using this method. First described by Guardio Labs in 2023, EtherHiding is a malware distribution technique where payloads are embedded within smart contracts on a public blockchain (Binance Smart Chain or Ethereum). The threat actor can thus host malicious scripts and retrieve them when needed. Due to how blockchains work, EtherHiding offers anonimity, resistance to takedown actions and allows flexible payload updating, all at a very low cost. Furthermore, fetching the payloads is possible through read-only calls that leave no visible transaction history, adding stealth to the process. The attacks typically begin fake job interviews, a hallmark for DPRK's hallmark social engineering tactics, from carefully fabricated entities (BlockNovas LLC, Angeloper Agency, SoftGlide LLC) targeting software and web developers. The victim is tricked into running code, as part of the interview's technical assessment, that executes a JavaScript downloader. The researchers say that "the smart contract hosts the JADESNOW downloader that i...
North Korean hackers use EtherHiding to hide malware on the blockchain
BleepingComputer
·Bill Toulas
·Published Oct 16, 2025
·Updated
Affected Software
2 affected components
Ethereum Smart Contract
Binance Smart Chain
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses North Korean hackers using a technique called EtherHiding to conceal malware within blockchain smart contracts.
2
What security implications are discussed in the article?
The article highlights the risks posed by malware delivery through legitimate smart contracts, potentially leading to cryptocurrency theft.
3
What types of smart contracts are involved in this attack?
The attacks involve Ethereum Smart Contracts and Binance Smart Chain contracts.
4
How do the hackers utilize social engineering in their campaigns?
Hackers leverage social engineering tactics to trick users into interacting with their malware-laden smart contracts.
5
What method is used by the North Korean hackers to hide the malware?
The hackers utilize the EtherHiding technique, which embeds malware into the blockchain via smart contracts.