North Korean hackers are deploying new malware to steal cryptocurrency using EtherHiding without detection, which symbolizes the dawn of blockchain-based cyberattacks. According to cybersecurity teams, UNC5342, a state-sponsored group, is the first nation-state that uses EtherHiding for malware attacks and crypto theft.   According to the Google Threat Intelligence Group (GTIG), which was reported by The […] The post Crypto Hack News: North Korean Hackers Exploit EtherHiding for Crypto Thefts appeared first on Live Bitcoin News.North Korean hackers are deploying new malware to steal cryptocurrency using EtherHiding without detection, which symbolizes the dawn of blockchain-based cyberattacks. According to cybersecurity teams, UNC5342, a state-sponsored group, is the first nation-state that uses EtherHiding for malware attacks and crypto theft.   According to the Google Threat Intelligence Group (GTIG), which was reported by The […] The post Crypto Hack News: North Korean Hackers Exploit EtherHiding for Crypto Thefts appeared first on Live Bitcoin News.

Crypto Hack News: North Korean Hackers Exploit EtherHiding for Crypto Thefts

2025/10/18 08:00
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

North Korean hackers are deploying new malware to steal cryptocurrency using EtherHiding without detection, which symbolizes the dawn of blockchain-based cyberattacks.

According to cybersecurity teams, UNC5342, a state-sponsored group, is the first nation-state that uses EtherHiding for malware attacks and crypto theft.  

According to the Google Threat Intelligence Group (GTIG), which was reported by The Hacker News, this method incorporates malicious code in the form of smart contracts on blockchains such as Ethereum and BNB Smart Chain (BSC).  

By turning the blockchain into a decentralized “dead drop”, the attackers make takedowns cumbersome, and it is not clear where the attack originated.  

It also gives attackers the ability to update smart contract malware at will while experiencing dynamic control with a low gas fee update cost.

Sneaky Social Engineering Targets Developers via LinkedIn

Dubbed the “Contagious Interview” hacking campaign, UNC5342 is a sophisticated social engineering campaign.  

Attackers create LinkedIn profiles that imitate recruiters and lure their targets to Telegram or Discord channels. There, they persuade the victims to run malicious code disguised as job tests.

The ultimate objective is to gain unauthorized access to developers’ devices, steal sensitive information, and seize crypto assets. These actions align with North Korea’s dual goals of cyber espionage and financial gain.

Complex Multi-Stage Malware Chain

The infection chain is for Windows, macOS, and Linux. First, it uses a downloader that appears as a JavaScript that looks like an npm package.  

Subsequent stages are BeaverTail, which is used to steal cryptocurrency wallets, and JADESNOW, which can interact with Ethereum smart contracts to download InvisibleFerret.  

InvisibleFerret, a JavaScript version of a Python backdoor, allows long-term data stealing and remote management of infected computers.  

The malware additionally has installed a portable Python interpreter to run additional credential stealers associated with Ethereum addresses.

A New Era of Blockchain-Enabled Cyber Threats

Cybersecurity researchers say this is a serious increase in cyber threats. Law enforcement takedowns are hampered by the “bulletproof” nature of the host layer, which is based on blockchain technology.  

According to Google’s security team, the attackers’ use of multiple blockchains in EtherHiding is significant. It shows how cybercriminals adapt by exploiting emerging technologies for their benefit.

The insight reveals that state-backed actors are exploiting decentralized technologies for crypto theft and espionage. This marks a troubling evolution in global cyber threats.

The post Crypto Hack News: North Korean Hackers Exploit EtherHiding for Crypto Thefts appeared first on Live Bitcoin News.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Why It Could Outperform Pepe Coin And Tron With Over $7m Already Raised

Why It Could Outperform Pepe Coin And Tron With Over $7m Already Raised

The post Why It Could Outperform Pepe Coin And Tron With Over $7m Already Raised appeared on BitcoinEthereumNews.com. Crypto News 17 September 2025 | 20:26 While meme tokens like Pepe Coin and established networks such as Tron attract headlines, many investors are now searching for projects that combine innovation, revenue-sharing and real-world utility. BlockchainFX ($BFX), currently in presale at $0.024 ahead of an expected $0.05 launch, is quickly becoming one of the best cryptos to buy today. With $7m already secured and a unique model spanning multiple asset classes, it is positioning itself as a decentralised super app and a contender to surpass older altcoins. Early Presale Pricing Creates A Rare Entry Point BlockchainFX’s presale pricing structure has been designed to reward early participants. At $0.024, buyers secure a lower entry price than later rounds, locking in a cost basis more than 50% below the projected $0.05 launch price. As sales continue to climb beyond $7m, each new stage automatically increases the token price. This built-in mechanism creates a clear advantage for early investors and explains why the project is increasingly cited in “best presales to buy now” discussions across the crypto space. High-Yield Staking Model Shares Platform Revenue Beyond its presale appeal, BlockchainFX is creating a high-yield staking model that gives holders a direct share of platform revenue. Every time a trade occurs on its platform, 70% of trading fees flow back into the $BFX ecosystem: 50% of collected fees are automatically distributed to stakers in both BFX and USDT. 20% is allocated to daily buybacks of $BFX, adding demand and price support. Half of the bought-back tokens are permanently burned, steadily reducing supply. Rewards are based on the size of each member’s BFX holdings and capped at $25,000 USDT per day to ensure sustainability. This structure transforms token ownership from a speculative bet into an income-generating position, a rare feature among today’s altcoins. A Multi-Asset Platform…
Share
BitcoinEthereumNews2025/09/18 03:35
SOL Rockets 30%, ADA Holds $0.90, BlockDAG Dominates With $407M Presale

SOL Rockets 30%, ADA Holds $0.90, BlockDAG Dominates With $407M Presale

The post SOL Rockets 30%, ADA Holds $0.90, BlockDAG Dominates With $407M Presale appeared on BitcoinEthereumNews.com. The recent Solana (SOL) price surge has impressed traders, but questions remain about whether it can hold support after such a sharp climb. Meanwhile, the Cardano (ADA) market trend shows steady growth, yet its gains feel slower compared to rivals, leaving many wondering if ADA can really break past resistance. So where should investors look when both face their own hurdles? That’s where BlockDAG comes in. While others rely on speculation, BlockDAG is showing proof that rewards are already flowing. Social platforms are filled with photos and unboxing clips of the X10 miner, with users setting up devices and sharing payouts. This isn’t just talk; it’s miners at home already getting paid. For anyone searching for the best crypto to invest in now, BlockDAG stands out by combining real hardware delivery with immediate earning potential. BlockDAG: Proof in the Boxes, Proof in the Rewards BlockDAG’s biggest flex right now isn’t just numbers on a dashboard; it’s the boxes arriving at people’s doors. Across social media, users are posting photos, clips, and setup videos of the X10 miner. You can see them unboxing, plugging in, and instantly starting to mine BDAG. That kind of visibility shows BlockDAG isn’t selling hype; it’s already putting real mining gear into the hands of its backers. The community is not waiting for mainnet to find out if this works; they’re already mining and sharing payouts from home. While other coins are still tied up in speculation, here you’ve got thousands of miners being delivered worldwide. That’s why people are calling it the best crypto to invest in now, because it’s showing action, not just promises. The presale itself is backing up the momentum. BlockDAG has already raised over $407 million, with $40 million pouring in just last month. More than 312,000 holders are locked in,…
Share
BitcoinEthereumNews2025/09/18 08:52
‘Gold Pillars Crumbling?’ Strategist Questions Durability of Gold’s Geopolitical Bid

‘Gold Pillars Crumbling?’ Strategist Questions Durability of Gold’s Geopolitical Bid

Gold’s geopolitical premium may be fading as crude oil and silver eye powerful upside, with shifting global tensions and market volatility poised to redraw the
Share
Coinstats2026/03/04 10:30