MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: North Korean Hackers Use ‘EtherHiding’ to Spread Malicious Crypto Wallets, Mandiant Warns – Blockonomi
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$76,047.002.34%
  • ethereumEthereum(ETH)$2,320.421.74%
  • tetherTether(USDT)$1.000.00%
  • rippleXRP(XRP)$1.431.71%
  • binancecoinBNB(BNB)$631.361.70%
  • usd-coinUSDC(USDC)$1.000.02%
  • solanaSolana(SOL)$85.671.84%
  • tronTRON(TRX)$0.328844-0.61%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.031.33%
  • dogecoinDogecoin(DOGE)$0.0956801.99%
Smart Contracts

North Korean Hackers Use ‘EtherHiding’ to Spread Malicious Crypto Wallets, Mandiant Warns – Blockonomi

Last updated: October 17, 2025 9:10 pm
Published: 6 months ago
Share

Mandiant links the campaign to DPRK’s financially motivated cyber operations.

A new cyber threat has emerged targeting cryptocurrency users through compromised WordPress websites. Security researchers at Mandiant, part of Google Cloud, have identified a North Korean hacking group using a novel technique known as EtherHiding to deploy malicious crypto wallets.

The campaign disguises its operations within the Binance Smart Chain (BSC), making detection difficult for traditional security tools. According to Mandiant’s recent report, the attacks highlight a growing sophistication in state-sponsored financial cybercrime.

Mandiant’s investigation revealed that the group, tracked as APT43, embedded malicious code within legitimate WordPress plug-ins using EtherHiding. This technique allows attackers to conceal payloads in blockchain-based smart contracts, enabling dynamic updates without relying on centralized servers.

Once a user visits an infected site, the injected JavaScript prompts them to download a fake crypto wallet or security update. These deceptive wallets drain funds once users import their private keys or connect to decentralized apps. The attackers’ blockchain-based infrastructure makes tracing their operations more complex.

Mandiant noted that the malicious code communicates with the Binance Smart Chain to retrieve obfuscated scripts. This method not only conceals the hackers’ identity but also uses blockchain immutability to ensure the payload remains live even if the original websites are cleaned.

Besides crypto holders, the campaign also targets developers and investors exploring Web3 projects. By compromising trusted WordPress plug-ins, the attackers exploit the credibility of widely used tools to reach unsuspecting victims across multiple platforms.

According to the report, EtherHiding fits into North Korea’s ongoing efforts to generate revenue for its government through cyber theft. Mandiant’s threat intelligence analysts identified overlaps between this campaign and previous DPRK-linked operations such as Lazarus Group and Kimsuky.

The group’s tactics focus on stealing digital assets rather than disrupting systems. Mandiant explained that EtherHiding is an evolution of prior DPRK methods that used centralized command-and-control servers. Moving payload delivery to blockchain networks allows the hackers to bypass takedowns and remain persistent.

Furthermore, Mandiant found that compromised sites distributed phishing wallets designed to mimic reputable applications like MetaMask or Trust Wallet. Victims installing these fake extensions unknowingly exposed seed phrases that granted the attackers direct access to their funds.

Cybersecurity experts warn that this operation demonstrates how state-backed hackers are integrating blockchain technology into offensive campaigns. The decentralization that underpins Web3 now doubles as a tool for evading detection.

Mandiant urged developers to verify plug-in authenticity and monitor blockchain transactions linked to suspicious domains. Organizations relying on WordPress or Web3 integrations were advised to strengthen endpoint protection and review on-chain scripts for hidden payloads.

Read more on Blockonomi

This news is powered by Blockonomi Blockonomi

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Fidelity Let’s You Go Full YOLO On Ethereum, but Should You?
FutureX Partners with Shakib Uddin’s Global Trade Bangladesh to Expand International Presence
Schiff’s Revenge: Gold Bug Mocks $BTC as HYPER Hits $31M
Stablecoin Surge: Threat or Boon?
Citi and Swift Achieve Breakthrough in Fiat-Crypto Settlement

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Best Crypto Lending Platforms to Earn Interest
Next Article 4 Best Cryptos to Buy Today: BlockDAG, Chainlink, Cardano, and TRON Set the Stage for 2025 Gains
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d