Tech »  Topic »  North Korean hackers found hiding crypto-stealing malware with Blockchain

North Korean hackers found hiding crypto-stealing malware with Blockchain


(Image credit: Shutterstock)
  • UNC5342 uses blockchain smart contracts to deliver crypto-stealing malware via EtherHiding
  • Fake jobs and coding challenges lure developers into triggering the JadeSnow loader and backdoor
  • Blockchain’s immutability makes malware hosting resilient

North Korean state-sponsored threat actors are now using public blockchains to host malicious code and deploy malware on target endpoints.

This is according to Google’s Threat Intelligence Group (GTIG), who said they observed UNC5342 using Ethereum and BNB to host droppers and ultimately deploy cryptocurrency-stealing malware against software and blockchain developers.

The technique is called EtherHiding. Instead of sending a malicious file directly to the victim (or otherwise tricking them into downloading it), they encode parts of the malware into blockchain transactions and smart contracts.

Major new malware strain targets crypto users via malicious ads - here's what we know, and how to stay safeUnder the radar - Google warns new Brickstorm malware was ...
Copyright of this story solely belongs to techradar.com . To see the full text click HERE