Blockchain AcademicsBlockchain Academics
Blockchain Turns Rogue: North Korean Hackers Exploit Ethereum and BNB to Hide Crypto-Stealing Malware

Blockchain Turns Rogue: North Korean Hackers Exploit Ethereum and BNB to Hide Crypto-Stealing Malware

North Korean hackers use Ethereum and BNB smart contracts to hide crypto-stealing malware, evading detection through blockchain immutability.

Blockchain Academics NewsroomOctober 17, 20252 min read
Share

In a chilling reminder of how innovation can be weaponized, cybersecurity researchers have uncovered a new campaign in which North Korean state-sponsored hackers are using public blockchains to conceal and distribute cryptocurrency-stealing malware. The group, identified by Google’s Threat Intelligence Group (GTIG) as UNC5342, has been embedding malicious code within Ethereum and BNB Smart Chain transactions, leveraging the transparency and immutability of blockchain itself to deliver harmful payloads.

The method, dubbed EtherHiding, represents a dangerous evolution in cybercrime tactics. Instead of sending malware directly to victims, attackers encode fragments of the malicious code into blockchain smart contracts. When unsuspecting users interact with these contracts—whether by clicking links, executing scripts, or connecting crypto wallets—the code retrieves further instructions, deploying a stealthy loader known as JadeSnow. This component installs the InvisibleFerret backdoor, a tool already linked to previous cryptocurrency thefts.

According to Google, the hackers’ primary targets are software engineers and Web3 developers, often lured by fake job offers or online coding challenges. The deception begins innocently: victims download files they believe are part of a recruitment or testing process. Behind the scenes, those files query the blockchain to fetch hidden malware components. By using decentralized networks, the attackers ensure that their operations remain resilient—immune to takedown efforts that typically disrupt centralized malware hosting.

“This represents a shift toward next-generation bulletproof hosting,” GTIG warned. The very attributes that make blockchain attractive for legitimate applications—its openness, permanence, and censorship resistance—also make it ideal for cybercriminals seeking to evade detection and control.

This is not the first time such tactics have been observed. Since 2023, threat groups like UNC5142 have been embedding malicious JavaScript in compromised WordPress sites that connect to the blockchain for further payloads. Over 14,000 infected websites have been identified so far, highlighting the growing overlap between traditional web exploits and decentralized infrastructures.

North Korea’s involvement in cryptocurrency-related attacks is well documented. U.S. intelligence agencies estimate that Pyongyang has stolen billions of dollars in digital assets to fund its weapons programs and state apparatus. With blockchain-based malware delivery, these campaigns have entered a new era—one in which the very technology designed for transparency and trust is being subverted to conceal crime.

As blockchain adoption accelerates across industries, the challenge for cybersecurity professionals is clear: they must now defend against threats that are not only decentralized but also nearly impossible to erase. The EtherHiding campaign underscores a broader truth—when trustless systems meet human ingenuity, even immutability can become a weapon.

Discussion

Loading comments...