MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: DPRK Hackers Use ‘EtherHiding’ to Host Malware on Ethereum, BNB Blockchains: Google – Decrypt
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$74,073.003.54%
  • ethereumEthereum(ETH)$2,274.567.84%
  • tetherTether(USDT)$1.00-0.01%
  • binancecoinBNB(BNB)$685.013.77%
  • rippleXRP(XRP)$1.484.56%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$94.076.30%
  • tronTRON(TRX)$0.2982580.60%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.000.00%
  • dogecoinDogecoin(DOGE)$0.1016195.48%
Smart Contracts

DPRK Hackers Use ‘EtherHiding’ to Host Malware on Ethereum, BNB Blockchains: Google – Decrypt

Last updated: October 21, 2025 3:50 pm
Published: 5 months ago
Share

The regime’s hackers have stolen over $2 billion so far in 2025 alone, most from the Bybit exchange breach.

Google’s Threat Intelligence Group has warned that North Korea is using EtherHiding — a malware that hides in blockchain smart contracts and enables cryptocurrency theft — in its cyber hacking operations, as 2025 looks set to be a record year for crypto heists by the rogue state.

Though Google researchers said EtherHiding has been used by financially motivated threat actors abusing blockchain to distribute infostealers since at least September 2023, this is the first time they have observed its use by a nation state. The malware is particularly resistant to conventional takedown and blocking methods.

“EtherHiding presents new challenges as traditional campaigns have usually been halted by blocking known domains and IPs,” the researchers said in a blog post, singling out smart contracts on BNB Smart Chain and Ethereum as having played host to malicious code. Malware authors could “leverage the blockchain to perform further malware propagation stages since smart contracts operate autonomously and cannot be shut down,” they added.

While security researchers can alert the community by tagging a contract as malicious on official blockchain scanners, they noted, “malicious activity can still be performed.”

North Korean hackers have stolen more than $2 billion so far this year, most of that coming from the $1.46 billion attack on crypto exchange Bybit in February, according to an October report by blockchain analytics firm Elliptic.

The DPRK has also been held responsible for attacks on LND.fi, WOO X and Seedify, as well as thirty other hacks, bringing the total amount stolen by the country to date to over $6 billion. These funds, according to intelligence agencies, help finance the country’s nuclear weapons and missile programs.

Obtained through a mix of social engineering, deploying malware and sophisticated cyber espionage, North Korea has developed a mix of tactics to gain access to the financial systems or sensitive data of companies. The regime has proven itself willing to go to great lengths to do so, including setting up fake companies and targeting developers with fake employment offers.

Cases reported to Decrypt also show North Korean hacking outfits are now hiring non-Koreans to use as fronts to help them pass interviews to get jobs at tech and crypto companies as employers become more wary of North Koreans posing as people from elsewhere for interviews. Attackers can also lure victims to video meetings or fake podcast recordings on platforms which then display error messages or prompt update downloads which contain malicious code.

North Korean hackers have also targeted conventional web infrastructure, uploading more than 300 malicious code packages to the npm registry, an open-source software repository used by millions of developers to share and install JavaScript software.

North Korea’s latest pivot to include EtherHiding in its arsenal was traced back to February 2025, and since then Google said it has tracked UNC5342 — a North Korean threat actor linked to the country’s hacking outfit FamousChollima — incorporating EtherHiding into its social engineering campaign Contagious Interview.

The use of the EtherHiding malware involves embedding malicious code into the smart contracts of public blockchains, and then targeting users through WordPress sites injected with a small piece of JavaScript code.

“When a user visits the compromised website, the loader script executes in their browser,” Google researchers explained. “This script then communicates with the blockchain to retrieve the main malicious payload stored in a remote server.”

They added that the malware deploys a read-only function call (such as eth_call), which doesn’t create a transaction on the blockchain. “This ensures the retrieval of the malware is stealthy and avoids transaction fees (i.e. gas fees),” they noted. “Once fetched, the malicious payload is executed on the victim’s computer. This can lead to various malicious activities, such as displaying fake login pages, installing information-stealing malware, or deploying ransomware.”

The researchers warned that it “underscores the continuous evolution” of cybercriminals’ tactics. “In essence, EtherHiding represents a shift toward next-generation bulletproof hosting, where the inherent features of blockchain technology are repurposed for malicious ends.”

Read more on Decrypt

This news is powered by Decrypt Decrypt

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Bitcoin Price Prediction: Wall Street Firms Are Buying the Dip – Massive Rebound Comes Next | Bitcoin Analysis | CryptoRank.io
Sky Frontier Foundation Estimates $611M in Sky Ecosystem Gross Revenue for 2026 with $21 Billion USDS Supply
IPO Genie Presale Could Turn $250 Into $250,000 By 2026. The New Presale Token Catching Investor Attention
Third Qatar Real Estate Forum kicks off in Doha – kuwaitTimes
Valory’s Decentralized AI Agents Aim to Bring Transparency and Control to DeFi Investors

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Legit Redefined: How RockToken is Building Trust, Profitability, and a Greener Blockchain Future
Next Article EIRIO Announces Plan to Launch Native Token EIO, Advancing Toward a New Era of Structured Smart Finance
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d