TLDR EtherHiding uses smart contracts to host malware on Ethereum and BNB Chain. Hackers compromise WordPress sites to inject JavaScript loaders. Malware hosted on blockchain is hard to detect and remove due to immutability. CLEARFAKE was the first known EtherHiding campaign in September 2023. North Korean state-sponsored hackers are now embedding malicious code into blockchain [...] The post North Korean Hackers Use Blockchain to Hide Malware in New Campaign appeared first on CoinCentral.TLDR EtherHiding uses smart contracts to host malware on Ethereum and BNB Chain. Hackers compromise WordPress sites to inject JavaScript loaders. Malware hosted on blockchain is hard to detect and remove due to immutability. CLEARFAKE was the first known EtherHiding campaign in September 2023. North Korean state-sponsored hackers are now embedding malicious code into blockchain [...] The post North Korean Hackers Use Blockchain to Hide Malware in New Campaign appeared first on CoinCentral.

North Korean Hackers Use Blockchain to Hide Malware in New Campaign

TLDR

  • EtherHiding uses smart contracts to host malware on Ethereum and BNB Chain.
  • Hackers compromise WordPress sites to inject JavaScript loaders.
  • Malware hosted on blockchain is hard to detect and remove due to immutability.
  • CLEARFAKE was the first known EtherHiding campaign in September 2023.

North Korean state-sponsored hackers are now embedding malicious code into blockchain networks to avoid detection. According to Google’s Threat Intelligence Group (GTIG), this new method—called EtherHiding—uses smart contracts on public blockchains like Ethereum and BNB Smart Chain to store malware. The campaign allows the attackers to deliver and control harmful code through systems that are nearly impossible to block or alter.

What Is EtherHiding and How It Works

GTIG explains that EtherHiding involves placing small code snippets into smart contracts, which are hosted on decentralized blockchain networks. These networks are immutable, meaning that once code is added, it cannot be deleted or modified. This makes it difficult for cybersecurity systems to take down or stop the malware.

The hackers start by compromising WordPress websites, often using stolen login data or unpatched software flaws. Once inside, they add a JavaScript loader into the site’s code. This loader reaches out to the blockchain and pulls malware from a remote location. Since this connection is off-chain, it leaves almost no transaction record and requires little to no gas fees.

GTIG found that this method has been active since at least September 2023. The campaign began under the name CLEARFAKE, which used fake browser update alerts to trick users into installing malicious software.

Why the Blockchain Makes Malware Harder to Remove

One of the key features of blockchain technology is that once data is recorded, it cannot be changed. This feature is now being used to hide and spread malware in a way that security teams cannot easily stop. Because the malware is hosted inside smart contracts, blocking or deleting it would require changes to the blockchain itself, which is not possible.

GTIG reports that the use of decentralized systems allows attackers to operate without being noticed. Most anti-malware tools do not check smart contracts for harmful code, so these threats can stay active for long periods without detection.

“Although smart contracts offer innovative ways to build decentralized applications, their unchangeable nature is leveraged in EtherHiding,” GTIG noted.

Citizen Lab researcher John Scott-Railton called EtherHiding an “early-stage experiment” and warned that it could be made more dangerous by using automation tools. He said that future versions might include code that targets blockchain systems directly, especially if those systems are linked to wallets or transaction platforms.

Shift in North Korean Cyber Strategy

Cybersecurity experts believe this method shows a change in North Korea’s cyber operations. Instead of only stealing cryptocurrency, hackers are now using the technology behind it to help distribute malware.

Data from blockchain analytics firm TRM Labs states that North Korean hackers have stolen more than $1.5 billion in cryptocurrency this year. Investigators say that the funds are used to support military projects and avoid global sanctions.

The use of EtherHiding makes it easier for attackers to stay online and move their tools between platforms. Since the code is hosted on decentralized networks, even taking down the original website does not stop the malware from spreading.

How Users and Developers Can Protect Against EtherHiding

GTIG advises users and web developers to take extra steps to secure their systems. They recommend blocking unknown scripts, disabling unauthorized downloads, and keeping WordPress plugins updated.

Security teams are also encouraged to start scanning smart contracts for malicious content. Since the code is public, researchers can label and track harmful contracts more easily if they know what to look for.

The group also stressed the need for tighter website security. Preventing the initial breach of WordPress sites is a key step in stopping these attacks before the loader can be installed.

The post North Korean Hackers Use Blockchain to Hide Malware in New Campaign appeared first on CoinCentral.

Market Opportunity
Smart Blockchain Logo
Smart Blockchain Price(SMART)
$0.004946
$0.004946$0.004946
-4.35%
USD
Smart Blockchain (SMART) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Ethereum unveils roadmap focusing on scaling, interoperability, and security at Japan Dev Conference

Ethereum unveils roadmap focusing on scaling, interoperability, and security at Japan Dev Conference

The post Ethereum unveils roadmap focusing on scaling, interoperability, and security at Japan Dev Conference appeared on BitcoinEthereumNews.com. Key Takeaways Ethereum’s new roadmap was presented by Vitalik Buterin at the Japan Dev Conference. Short-term priorities include Layer 1 scaling and raising gas limits to enhance transaction throughput. Vitalik Buterin presented Ethereum’s development roadmap at the Japan Dev Conference today, outlining the blockchain platform’s priorities across multiple timeframes. The short-term goals focus on scaling solutions and increasing Layer 1 gas limits to improve transaction capacity. Mid-term objectives target enhanced cross-Layer 2 interoperability and faster network responsiveness to create a more seamless user experience across different scaling solutions. The long-term vision emphasizes building a secure, simple, quantum-resistant, and formally verified minimalist Ethereum network. This approach aims to future-proof the platform against emerging technological threats while maintaining its core functionality. The roadmap presentation comes as Ethereum continues to compete with other blockchain platforms for market share in the smart contract and decentralized application space. Source: https://cryptobriefing.com/ethereum-roadmap-scaling-interoperability-security-japan/
Share
BitcoinEthereumNews2025/09/18 00:25
Husky Inu (HINU) Completes Move To $0.00020688

Husky Inu (HINU) Completes Move To $0.00020688

Husky Inu (HINU) has completed its latest price jump, rising from $0.00020628 to $0.00020688. The price jump is part of the project’s pre-launch phase, which began on April 1, 2025.
Share
Cryptodaily2025/09/18 01:10
SEC dismisses civil action against Gemini with prejudice

SEC dismisses civil action against Gemini with prejudice

The SEC was satisfied with Gemini’s agreement to contribute $40 million toward the full recovery of Gemini Earn investors’ assets lost as a result of the Genesis
Share
Coinstats2026/01/24 06:43