North Korean hackers are deploying new malware to steal cryptocurrency using EtherHiding without detection, which symbolizes the dawn of blockchain-based cyberattacks. According to cybersecurity teams, UNC5342, a state-sponsored group, is the first nation-state that uses EtherHiding for malware attacks and crypto theft.   According to the Google Threat Intelligence Group (GTIG), which was reported by The […] The post Crypto Hack News: North Korean Hackers Exploit EtherHiding for Crypto Thefts appeared first on Live Bitcoin News.North Korean hackers are deploying new malware to steal cryptocurrency using EtherHiding without detection, which symbolizes the dawn of blockchain-based cyberattacks. According to cybersecurity teams, UNC5342, a state-sponsored group, is the first nation-state that uses EtherHiding for malware attacks and crypto theft.   According to the Google Threat Intelligence Group (GTIG), which was reported by The […] The post Crypto Hack News: North Korean Hackers Exploit EtherHiding for Crypto Thefts appeared first on Live Bitcoin News.

Crypto Hack News: North Korean Hackers Exploit EtherHiding for Crypto Thefts

North Korean hackers are deploying new malware to steal cryptocurrency using EtherHiding without detection, which symbolizes the dawn of blockchain-based cyberattacks.

According to cybersecurity teams, UNC5342, a state-sponsored group, is the first nation-state that uses EtherHiding for malware attacks and crypto theft.  

According to the Google Threat Intelligence Group (GTIG), which was reported by The Hacker News, this method incorporates malicious code in the form of smart contracts on blockchains such as Ethereum and BNB Smart Chain (BSC).  

By turning the blockchain into a decentralized “dead drop”, the attackers make takedowns cumbersome, and it is not clear where the attack originated.  

It also gives attackers the ability to update smart contract malware at will while experiencing dynamic control with a low gas fee update cost.

Sneaky Social Engineering Targets Developers via LinkedIn

Dubbed the “Contagious Interview” hacking campaign, UNC5342 is a sophisticated social engineering campaign.  

Attackers create LinkedIn profiles that imitate recruiters and lure their targets to Telegram or Discord channels. There, they persuade the victims to run malicious code disguised as job tests.

The ultimate objective is to gain unauthorized access to developers’ devices, steal sensitive information, and seize crypto assets. These actions align with North Korea’s dual goals of cyber espionage and financial gain.

Complex Multi-Stage Malware Chain

The infection chain is for Windows, macOS, and Linux. First, it uses a downloader that appears as a JavaScript that looks like an npm package.  

Subsequent stages are BeaverTail, which is used to steal cryptocurrency wallets, and JADESNOW, which can interact with Ethereum smart contracts to download InvisibleFerret.  

InvisibleFerret, a JavaScript version of a Python backdoor, allows long-term data stealing and remote management of infected computers.  

The malware additionally has installed a portable Python interpreter to run additional credential stealers associated with Ethereum addresses.

A New Era of Blockchain-Enabled Cyber Threats

Cybersecurity researchers say this is a serious increase in cyber threats. Law enforcement takedowns are hampered by the “bulletproof” nature of the host layer, which is based on blockchain technology.  

According to Google’s security team, the attackers’ use of multiple blockchains in EtherHiding is significant. It shows how cybercriminals adapt by exploiting emerging technologies for their benefit.

The insight reveals that state-backed actors are exploiting decentralized technologies for crypto theft and espionage. This marks a troubling evolution in global cyber threats.

The post Crypto Hack News: North Korean Hackers Exploit EtherHiding for Crypto Thefts appeared first on Live Bitcoin News.

Market Opportunity
SecondLive Logo
SecondLive Price(LIVE)
$0.00004038
$0.00004038$0.00004038
-2.20%
USD
SecondLive (LIVE) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

CME Group to launch options on XRP and SOL futures

CME Group to launch options on XRP and SOL futures

The post CME Group to launch options on XRP and SOL futures appeared on BitcoinEthereumNews.com. CME Group will offer options based on the derivative markets on Solana (SOL) and XRP. The new markets will open on October 13, after regulatory approval.  CME Group will expand its crypto products with options on the futures markets of Solana (SOL) and XRP. The futures market will start on October 13, after regulatory review and approval.  The options will allow the trading of MicroSol, XRP, and MicroXRP futures, with expiry dates available every business day, monthly, and quarterly. The new products will be added to the existing BTC and ETH options markets. ‘The launch of these options contracts builds on the significant growth and increasing liquidity we have seen across our suite of Solana and XRP futures,’ said Giovanni Vicioso, CME Group Global Head of Cryptocurrency Products. The options contracts will have two main sizes, tracking the futures contracts. The new market will be suitable for sophisticated institutional traders, as well as active individual traders. The addition of options markets singles out XRP and SOL as liquid enough to offer the potential to bet on a market direction.  The options on futures arrive a few months after the launch of SOL futures. Both SOL and XRP had peak volumes in August, though XRP activity has slowed down in September. XRP and SOL options to tap both institutions and active traders Crypto options are one of the indicators of market attitudes, with XRP and SOL receiving a new way to gauge sentiment. The contracts will be supported by the Cumberland team.  ‘As one of the biggest liquidity providers in the ecosystem, the Cumberland team is excited to support CME Group’s continued expansion of crypto offerings,’ said Roman Makarov, Head of Cumberland Options Trading at DRW. ‘The launch of options on Solana and XRP futures is the latest example of the…
Share
BitcoinEthereumNews2025/09/18 00:56
Bipartisan Bill Targets Crypto Tax Loopholes and Stablecoin Rules: Report

Bipartisan Bill Targets Crypto Tax Loopholes and Stablecoin Rules: Report

Bipartisan House members Max Miller (R-Ohio) and Steven Horsford (D-Nev.) are moving to simplify the tax treatment of digital assets with the introduction of the
Share
Tronweekly2025/12/21 08:46
Vitalik Buterin Reveals Ethereum’s Long-Term Focus on Quantum Resistance

Vitalik Buterin Reveals Ethereum’s Long-Term Focus on Quantum Resistance

TLDR Ethereum focuses on quantum resistance to secure the blockchain’s future. Vitalik Buterin outlines Ethereum’s long-term development with security goals. Ethereum aims for improved transaction efficiency and layer-2 scalability. Ethereum maintains a strong market position with price stability above $4,000. Vitalik Buterin, the co-founder of Ethereum, has shared insights into the blockchain’s long-term development. During [...] The post Vitalik Buterin Reveals Ethereum’s Long-Term Focus on Quantum Resistance appeared first on CoinCentral.
Share
Coincentral2025/09/18 00:31