Threat Advisory

UNC5342 Deploys JADESNOW and INVISIBLEFERRET Against Crypto Developers

Threat: Malware Campaign
Threat Actor Name: UNC5342
Threat Actor Type: -
Targeted Region: Global
Alias: -
Threat Actor Region: North Korea (Dprk)
Targeted Sector: Technology & IT, Finance & Banking
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Researchers identified a state-sponsored threat group using EtherHiding to deliver malware and steal cryptocurrency, marking the first known case of a nation-state adopting this blockchain-based method. EtherHiding uses public blockchains such as Ethereum and BNB Smart Chain to embed and distribute malicious code, transforming decentralized networks into resilient command-and-control systems that cannot be easily taken down. The group integrated EtherHiding into a long-running social engineering campaign called Contagious Interview , which targets developers through fake job opportunities. Victims are deceived into downloading malicious files disguised as coding assessments or technical tests, leading to the deployment of JADESNOW malware that delivers a JavaScript variant of INVISIBLEFERRET . The campaign–s intent combines financial gain through cryptocurrency theft with intelligence gathering from technology-focused individuals.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Researchers identified a state-sponsored threat group using EtherHiding to deliver malware and steal cryptocurrency, marking the first known case of a nation-state adopting this blockchain-based method. EtherHiding uses public blockchains such as Ethereum and BNB Smart Chain to embed and distribute malicious code, transforming decentralized networks into resilient command-and-control systems that cannot be easily taken down. The group integrated EtherHiding into a long-running social engineering campaign called Contagious Interview , which targets developers through fake job opportunities. Victims are deceived into downloading malicious files disguised as coding assessments or technical tests, leading to the deployment of JADESNOW malware that delivers a JavaScript variant of INVISIBLEFERRET . The campaign–s intent combines financial gain through cryptocurrency theft with intelligence gathering from technology-focused individuals.[emaillocker id="1283"]

EtherHiding represents an evolution in cyber operations where blockchain technology is repurposed for malicious use. The technique embeds JavaScript payloads into smart contracts stored on public blockchains, allowing attackers to retrieve and execute code using read-only calls that leave no traceable transactions. Once triggered, the loader script downloads encrypted payloads that install multi-stage malware such as JADESNOW INVISIBLEFERRET . The JADESNOW component decodes and executes payloads directly from blockchain data, making detection extremely difficult, while INVISIBLEFERRET establishes remote access for data theft and command execution. Attackers frequently switch between blockchain networks like Ethereum and BNB Smart Chain to obscure their infrastructure and reduce costs, complicating analysis.

This approach demonstrates a use of blockchain immutability to ensure persistence, blending decentralized hosting with flexible control to maintain resilient operations that traditional defensive measures struggle to disrupt. The use of EtherHiding by a nation-backed group marks a turning point in how decentralized technology can be exploited for long-term cyber operations. While the blockchain–s immutable nature makes direct removal impossible, the reliance on centralized API services and explorer tools introduces limited opportunities for monitoring and disruption. EtherHiding–s decentralized structure challenges conventional defenses such as domain or IP blocking, forcing a shift toward centralized browser management and policy enforcement to prevent infection. The campaign also underscores how social engineering remains a key entry point, enabling advanced payload delivery through trusted communication channels. By combining deception, cross-chain techniques, and adaptive malware delivery, this operation illustrates a growing trend where adversaries exploit the resilience of Web3 infrastructure for both financial theft and espionage. The findings emphasize the need for proactive detection models capable of tracing malicious blockchain interactions and countering next-generation decentralized threats.

THREAT PROFILE:

Tactic Technique ID Technique Sub-technique
Initial Access T1566.002 Phishing Spearphishing Link
Initial Access T1195.002 Supply Chain Compromise Compromise Software Supply Chain
Execution T1059.007 Command and scripting interpreter JavaScript
Execution T1204.002 User Execution Malicious File
Persistence T1547 Boot or Logon Autostart Execution
Defense Evasion T1027 Obfuscated Files or Information
Collection T1056 Input Capture Web Portal Capture
Command and Control T1071.001 Application Layer Protocol Web Protocol
Command and Control T1095 Non-Standard Port
Exfiltration T1041 Exfiltration Over C2 Channel

MBC MAPPING:

Objective Behaviour ID Behaviour
Defense Evasion B0040.002 Steganography
Command and Control B0030.002 Receive Data
C0002.002 HTTP Communication (Client)
Anti-Static Analysis E1027.m03 Encoding - Custom Algorithm
Anti-Behavioral Analysis B0007.003 Human User Check
Lateral Movement E1105 Ingress Tool Transfer
Discovery E1082.m02 Enumerate Environment Variables
Execution E1059 Command and Scripting Interpreter
Collection C0051 Read File
Persistence F0012 Registry Run Keys / Startup Folder

REFERENCES:

The following reports contain further
https://cybersecuritynews.com/north-korean-hackers-using-etherhiding/
https://cloud.google.com/blog/topics/threat-intelligence/dprk-adopts-etherhiding

[/emaillocker]
crossmenu