Skip to content
← Back to newsNorth Korean Hackers Exploit Smart Contracts with 'EtherHiding' Malware to Steal Crypto
Security

North Korean Hackers Exploit Smart Contracts with 'EtherHiding' Malware to Steal Crypto

By ToTo BugelmanNewcomer0 rep· 10/18/2025

Google's Threat Intelligence Group has identified a sophisticated new tactic employed by North Korean hackers, dubbed "EtherHiding." This method involves embedding malicious code within smart contracts on public blockchain networks to steal cryptocurrency and sensitive data. The technique, which surfaced in 2023, often leverages social engineering to lure victims into compromising their systems.

 

Key Takeaways

  • North Korean hackers are using a technique called "EtherHiding" to embed crypto-stealing malware in smart contracts.

  • The attack often begins with social engineering, such as fake job offers, to direct victims to malicious websites.

  • Compromised websites use "read-only" blockchain functions to avoid detection and transaction fees.

  • The malware can escalate to steal sensitive data and provide long-term access to compromised systems.

 

The EtherHiding Attack Method

Attackers begin by compromising legitimate website addresses using a Loader Script. They then inject JavaScript code into the website. This code triggers a separate malicious package hidden within a smart contract. When a user interacts with the compromised site, the malware is activated, aiming to steal funds and data.

 

Google Cloud

 

Evading Detection

Crucially, the compromised website communicates with the blockchain network using a "read-only" function. This allows threat actors to avoid creating actual transactions on the ledger, thereby evading detection and minimizing associated transaction fees, according to Google researchers.

 

Social Engineering Tactics

The EtherHiding campaign frequently targets software and cryptocurrency developers. Threat actors establish fake companies, recruitment agencies, and online profiles to present enticing fake employment offers. Communications are often moved to platforms like Discord or Telegram, where victims are prompted to complete coding tests or employment assessments.

 

Malware Deployment Stages

During the technical assessment phase, victims are typically instructed to download malicious files from code repositories like GitHub. In other scenarios, attackers may initiate a video call, display a fake error message, and prompt the user to download a software patch that contains the malicious code. Once installed, a second-stage JavaScript-based malware known as "JADESNOW" is deployed to exfiltrate sensitive data. For high-value targets, a third stage can grant attackers persistent access to the compromised machine and connected network systems.

 

Sources

 

This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.

 

Discussion (0)

Sign in to join the discussion.

No comments yet. Be the first.

North Korean Hackers Exploit Smart Contracts with 'EtherHiding' Malware to Steal Crypto | BlockzHub