Close Menu
BlockLifeNewsBlockLifeNews
    What's Hot

    Can Beyond Meat Match the GameStop Meme Stock Craze?

    37 minutes ago

    Bitcoin Price Slides Lower — Bears Tighten Grip Amid Weak Market Sentiment

    44 minutes ago

    Peter Thiel-backed ETHZilla to acquire 15% stake in Satschel for $15M

    48 minutes ago
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    Login
    BlockLifeNewsBlockLifeNews
    Market Data
    Subscribe
    Thursday, October 23
    • Home
    • News
      • Bitcoin
      • Ethereum
      • Altcoin
      • Meme Coins
    • DeFi
    • Blockchain
    • Analysis
    • NFTs
    • AI
    • Finance
    • GameFi
    • Mining
    • Trading
    • Learn
    BlockLifeNewsBlockLifeNews
    • News
    • Bitcoin
    • Ethereum
    • Altcoin
    • Blockchain
    • Analysis
    • AI
    • DeFi
    • Finance
    • GameFi
    • Meme Coins
    • Mining
    • NFTs
    • Trading
    • Learn
    Home»News
    News

    DPRK Hackers Use ‘EtherHiding’ to Host Malware on Ethereum, BNB Blockchains: Google

    News RoomBy News Room2 days agoNo Comments4 Mins Read
    Facebook Twitter LinkedIn Telegram WhatsApp Threads Copy Link Email

    Listen to the article

    0:00
    0:00

    Key Takeaways

    🌐 Translate Article

    Translating...

    📖 Read Along

    💬 AI Assistant

    🤖
    Hi! I'm here to help you understand this article. Ask me anything about the content!

    In brief

    • Google Threat Intelligence Group researchers have uncovered North Korean hackers using EtherHiding malware.
    • EtherHiding enables stealthy, untraceable malware delivery through smart contracts.
    • The regime’s hackers have stolen over $2 billion so far in 2025 alone, most from the Bybit exchange breach.

    Google’s Threat Intelligence Group has warned that North Korea is using EtherHiding—a malware that hides in blockchain smart contracts and enables cryptocurrency theft—in its cyber hacking operations, as 2025 looks set to be a record year for crypto heists by the rogue state.

    Though Google researchers said EtherHiding has been used by financially motivated threat actors abusing blockchain to distribute infostealers since at least September 2023, this is the first time they have observed its use by a nation state. The malware is particularly resistant to conventional takedown and blocking methods.

    “EtherHiding presents new challenges as traditional campaigns have usually been halted by blocking known domains and IPs,” the researchers said in a blog post, singling out smart contracts on BNB Smart Chain and Ethereum as having played host to malicious code. Malware authors could “leverage the blockchain to perform further malware propagation stages since smart contracts operate autonomously and cannot be shut down,” they added.

    While security researchers can alert the community by tagging a contract as malicious on official blockchain scanners, they noted, “malicious activity can still be performed.”

    The North Korean hacking threat

    North Korean hackers have stolen more than $2 billion so far this year, most of that coming from the $1.46 billion attack on crypto exchange Bybit in February, according to an October report by blockchain analytics firm Elliptic.

    The DPRK has also been held responsible for attacks on LND.fi, WOO X and Seedify, as well as thirty other hacks, bringing the total amount stolen by the country to date to over $6 billion. These funds, according to intelligence agencies, help finance the country’s nuclear weapons and missile programs.

    Obtained through a mix of social engineering, deploying malware and sophisticated cyber espionage, North Korea has developed a mix of tactics to gain access to the financial systems or sensitive data of companies. The regime has proven itself willing to go to great lengths to do so, including setting up fake companies and targeting developers with fake employment offers.

    Cases reported to Decrypt also show North Korean hacking outfits are now hiring non-Koreans to use as fronts to help them pass interviews to get jobs at tech and crypto companies as employers become more wary of North Koreans posing as people from elsewhere for interviews. Attackers can also lure victims to video meetings or fake podcast recordings on platforms which then display error messages or prompt update downloads which contain malicious code.

    North Korean hackers have also targeted conventional web infrastructure, uploading more than 300 malicious code packages to the npm registry, an open-source software repository used by millions of developers to share and install JavaScript software.

    How does EtherHiding work?

    North Korea’s latest pivot to include EtherHiding in its arsenal was traced back to February 2025, and since then Google said it has tracked UNC5342—a North Korean threat actor linked to the country’s hacking outfit FamousChollima—incorporating EtherHiding into its social engineering campaign Contagious Interview.

    The use of the EtherHiding malware involves embedding malicious code into the smart contracts of public blockchains, and then targeting users through WordPress sites injected with a small piece of JavaScript code.

    “When a user visits the compromised website, the loader script executes in their browser,”  Google researchers explained. “This script then communicates with the blockchain to retrieve the main malicious payload stored in a remote server.”

    They added that the malware deploys a read-only function call (such as eth_call), which doesn’t create a transaction on the blockchain. “This ensures the retrieval of the malware is stealthy and avoids transaction fees (i.e. gas fees),” they noted. “Once fetched, the malicious payload is executed on the victim’s computer. This can lead to various malicious activities, such as displaying fake login pages, installing information-stealing malware, or deploying ransomware.”

    The researchers warned that it “underscores the continuous evolution” of cybercriminals’ tactics. “In essence, EtherHiding represents a shift toward next-generation bulletproof hosting, where the inherent features of blockchain technology are repurposed for malicious ends.”

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

    Read the author’s full story here
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    News Room
    • Website
    • Facebook
    • X (Twitter)
    • Instagram
    • LinkedIn

    News Room is the editorial team behind BlockedCubed, delivering timely news and insights on cryptocurrency, blockchain, and digital finance. Dedicated to clarity and accuracy, the team covers global trends shaping the future of crypto.

    Keep Reading

    Can Beyond Meat Match the GameStop Meme Stock Craze?

    Canada Hits Crypto Firm With $126 Million Fine

    Alleged ‘Trump Insider Whale’ Closes $200 Million Bitcoin Short

    Reddit Sues Perplexity AI, Alleging ‘Industrial-Scale’ Data Theft

    Ledger’s Latest Nano Crypto Hardware Wallet Offers a Punch of Personality

    Morning Minute: Crypto Caught in Middle of Democrat vs Republican Battle

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Bitcoin Price Slides Lower — Bears Tighten Grip Amid Weak Market Sentiment

    44 minutes ago

    Peter Thiel-backed ETHZilla to acquire 15% stake in Satschel for $15M

    48 minutes ago

    MegaETH Pre-Market Valuation Taps $6 Billion

    50 minutes ago

    Can Decentralized Networks Make the Internet More Resilient?

    51 minutes ago

    Latest Articles

    Could South Korea’s Risk Appetite Power New Crypto Trends?

    1 hour ago

    Canada Hits Crypto Firm With $126 Million Fine

    2 hours ago

    Peter Schiff: Bitcoin Going to Zero

    2 hours ago

    Daily Newsletter

    Get the latest crypto news and updates directly to your inbox.

    Blocklifenews Logo
    Facebook X (Twitter) TikTok Instagram LinkedIn

    News

    • Bitcoin
    • Ethereum
    • Altcoin
    • Meme Coins
    • DeFi
    • Blockchain
    • NFTs

    Quick Links

    • Analysis
    • Trading
    • Learn
    • Market Data
    • Price Prediction
    • Newsletter

    Company

    • About us
    • Privacy Policy
    • Cookies Policy
    • Terms of use
    • Our Authors
    • Advertise
    • Press Release

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2025 Blocklifenews. All Rights Reserved.

    • Privacy Policy
    • Terms
    • Contact

    Type above and press Enter to search. Press Esc to cancel.

    Sign In or Register

    Welcome Back!

    Login to your account below.

    Lost password?