Find notable cyber news and cases, enriched with sources, timelines, and signals.

EtherHiding JADESNOW downloader malware activity

Malware Activity
First reported
Last updated
Happening score
H score 29
2 unique sources, 2 articles

Summary

Hide ▲

North Korean threat actor UNC5342 is using EtherHiding in the Contagious Interview campaign to deliver malware and support cryptocurrency theft. Google Threat Intelligence Group said it has seen the actor use the technique since February 2025, and described it as the first observed nation-state actor adoption of EtherHiding. The chain uses fake recruiting fronts such as BlockNovas LLC, Angeloper Agency, and SoftGlide LLC to target developers with a JavaScript downloader that retrieves JADESNOW from smart contracts on Ethereum or BNB Smart Chain and can lead to INVISIBLEFERRET-style payloads, credential theft, and in-memory execution.

Related Happenings

FROST browser SSD timing side channel via OPFS

Technical Analysis
H score16 First: 09.06.2026 12:50 Last: 09.06.2026 12:50 Sources 1

About this happening: FROST turns browser storage timing into a remote SSD side channel that can identify which sites a user visits and which apps they open. The technique runs insi...

Gremlin stealer modular toolkit evolution

Malware Activity
H score21 First: 15.05.2026 17:19 Last: 15.05.2026 17:19 Sources 1

About this happening: The Gremlin stealer malware has expanded into a modular toolkit with session-hijacking and crypto clipping capabilities, raising the risk of credential theft and a...

Vidar infostealer market rise and distribution expansion

Malware Activity
H score30 First: 28.04.2026 22:07 Last: 28.04.2026 22:07 Sources 1

About this happening: Vidar remains a long-running infostealer threat, and Aryaka reported a fresh campaign in recent weeks that adds new obfuscation techniques and stronger steal...

AgingFly malware attacks local governments and hospitals in Ukraine

Malware Activity
H score28 First: 16.04.2026 00:57 Last: 16.04.2026 00:57 Sources 1

About this happening: The AgingFly malware is now being deployed against local governments and hospitals in Ukraine, where it steals browser and WhatsApp authentication data and enables dee...

Storm infostealer server-side decryption activity

Malware Activity
H score18 First: 02.04.2026 17:15 Last: 02.04.2026 17:15 Sources 1

About this happening: The Storm infostealer now steals browser credentials, session cookies, and crypto wallets and forwards them to attacker infrastructure for server-side decryption...

Timeline

  1. 16.10.2025 17:00 3 articles · 9mo ago

    GTIG discloses UNC5342 EtherHiding campaign

    Initial Disclosure

    Google Threat Intelligence Group (GTIG) says North Korean threat actor UNC5342 has used EtherHiding since February 2025 in Contagious Interview operations, using fabricated job interview fronts such as BlockNovas LLC, Angeloper Agency, and SoftGlide LLC to target software and web developers with a JavaScript downloader that retrieves JADESNOW from smart contracts on Ethereum or the BNB Smart Chain and can lead to an InvisibleFerret-style payload, credential theft, and in-memory execution.

    Show sources