EtherHiding JADESNOW downloader malware activity
Malware Activity
Summary
Hide ▲
Show ▼
North Korean threat actor UNC5342 is using EtherHiding in the Contagious Interview campaign to deliver malware and support cryptocurrency theft. Google Threat Intelligence Group said it has seen the actor use the technique since February 2025, and described it as the first observed nation-state actor adoption of EtherHiding. The chain uses fake recruiting fronts such as BlockNovas LLC, Angeloper Agency, and SoftGlide LLC to target developers with a JavaScript downloader that retrieves JADESNOW from smart contracts on Ethereum or BNB Smart Chain and can lead to INVISIBLEFERRET-style payloads, credential theft, and in-memory execution.
Related Happenings
FROST browser SSD timing side channel via OPFS
Technical Analysis
H score16
First: 09.06.2026 12:50
Last: 09.06.2026 12:50
Sources 1
About this happening:
FROST turns browser storage timing into a remote SSD side channel that can identify which sites a user visits and which apps they open. The technique runs insi...
FROST browser SSD timing side channel via OPFS
Technical AnalysisAbout this happening: FROST turns browser storage timing into a remote SSD side channel that can identify which sites a user visits and which apps they open. The technique runs insi...
Gremlin stealer modular toolkit evolution
Malware Activity
H score21
First: 15.05.2026 17:19
Last: 15.05.2026 17:19
Sources 1
About this happening:
The Gremlin stealer malware has expanded into a modular toolkit with session-hijacking and crypto clipping capabilities, raising the risk of credential theft and a...
Gremlin stealer modular toolkit evolution
Malware ActivityAbout this happening: The Gremlin stealer malware has expanded into a modular toolkit with session-hijacking and crypto clipping capabilities, raising the risk of credential theft and a...
Vidar infostealer market rise and distribution expansion
Malware Activity
H score30
First: 28.04.2026 22:07
Last: 28.04.2026 22:07
Sources 1
About this happening:
Vidar remains a long-running infostealer threat, and Aryaka reported a fresh campaign in recent weeks that adds new obfuscation techniques and stronger steal...
Vidar infostealer market rise and distribution expansion
Malware ActivityAbout this happening: Vidar remains a long-running infostealer threat, and Aryaka reported a fresh campaign in recent weeks that adds new obfuscation techniques and stronger steal...
AgingFly malware attacks local governments and hospitals in Ukraine
Malware Activity
H score28
First: 16.04.2026 00:57
Last: 16.04.2026 00:57
Sources 1
About this happening:
The AgingFly malware is now being deployed against local governments and hospitals in Ukraine, where it steals browser and WhatsApp authentication data and enables dee...
AgingFly malware attacks local governments and hospitals in Ukraine
Malware ActivityAbout this happening: The AgingFly malware is now being deployed against local governments and hospitals in Ukraine, where it steals browser and WhatsApp authentication data and enables dee...
Storm infostealer server-side decryption activity
Malware Activity
H score18
First: 02.04.2026 17:15
Last: 02.04.2026 17:15
Sources 1
About this happening:
The Storm infostealer now steals browser credentials, session cookies, and crypto wallets and forwards them to attacker infrastructure for server-side decryption...
Storm infostealer server-side decryption activity
Malware ActivityAbout this happening: The Storm infostealer now steals browser credentials, session cookies, and crypto wallets and forwards them to attacker infrastructure for server-side decryption...
Timeline
-
16.10.2025 17:00 3 articles · 9mo ago
GTIG discloses UNC5342 EtherHiding campaign
Initial DisclosureGoogle Threat Intelligence Group (GTIG) says North Korean threat actor UNC5342 has used EtherHiding since February 2025 in Contagious Interview operations, using fabricated job interview fronts such as BlockNovas LLC, Angeloper Agency, and SoftGlide LLC to target software and web developers with a JavaScript downloader that retrieves JADESNOW from smart contracts on Ethereum or the BNB Smart Chain and can lead to an InvisibleFerret-style payload, credential theft, and in-memory execution.
Show sources
- North Korean hackers use EtherHiding to hide malware on the blockchain — www.bleepingcomputer.com — 16.10.2025 17:00
- North Korean hackers use EtherHiding to hide malware on the blockchain — www.bleepingcomputer.com — 16.10.2025 17:00
- North Korean Hackers Use EtherHiding to Steal Crypto — www.infosecurity-magazine.com — 17.10.2025 16:14