• News/
  • https://www.bleepingcomputer.com/news/security/north-korean-hackers-use-etherhiding-to-hide-malware-on-the-blockchain/

North Korean hackers use EtherHiding to hide malware on the blockchain

BleepingComputer
·
Bill Toulas
·
Published Oct 16, 2025
·
Updated

North Korean hackers have adopted the 'EtherHiding' technique that leverages smart contracts to host and deliver malware in social engineering campaigns that steal cryptocurrency. Google Threat Intelligence Group (GTIG) says that a DPRK nation state threat actor, tracked internally as UNC5342, has been employing EtherHiding since February in Contagious Interview operations. The researchers note that this is the first time they saw a state-backed hacker group using this method. First described by Guardio Labs in 2023, EtherHiding is a malware distribution technique where payloads are embedded within smart contracts on a public blockchain (Binance Smart Chain or Ethereum). The threat actor can thus host malicious scripts and retrieve them when needed. Due to how blockchains work, EtherHiding offers anonimity, resistance to takedown actions and allows flexible payload updating, all at a very low cost. Furthermore, fetching the payloads is possible through read-only calls that leave no visible transaction history, adding stealth to the process. The attacks typically begin fake job interviews, a hallmark for DPRK's hallmark social engineering tactics, from carefully fabricated entities (BlockNovas LLC, Angeloper Agency, SoftGlide LLC) targeting software and web developers. The victim is tricked into running code, as part of the interview's technical assessment, that executes a JavaScript downloader. The researchers say that "the smart contract hosts the JADESNOW downloader that i...

Read full article

Affected Software

2 affected components
Ethereum Smart Contract
Binance Smart Chain

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses North Korean hackers using a technique called EtherHiding to conceal malware within blockchain smart contracts.

2

What security implications are discussed in the article?

The article highlights the risks posed by malware delivery through legitimate smart contracts, potentially leading to cryptocurrency theft.

3

What types of smart contracts are involved in this attack?

The attacks involve Ethereum Smart Contracts and Binance Smart Chain contracts.

4

How do the hackers utilize social engineering in their campaigns?

Hackers leverage social engineering tactics to trick users into interacting with their malware-laden smart contracts.

5

What method is used by the North Korean hackers to hide the malware?

The hackers utilize the EtherHiding technique, which embeds malware into the blockchain via smart contracts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203