Google's Threat Intelligence Group has identified a sophisticated new tactic employed by North Korean hackers, dubbed "EtherHiding." This method involves embedding malicious code within smart contracts on public blockchain networks to steal cryptocurrency and sensitive data. The technique, which surfaced in 2023, often leverages social engineering to lure victims into compromising their systems.
Key Takeaways
-
North Korean hackers are using a technique called "EtherHiding" to embed crypto-stealing malware in smart contracts.
-
The attack often begins with social engineering, such as fake job offers, to direct victims to malicious websites.
-
Compromised websites use "read-only" blockchain functions to avoid detection and transaction fees.
-
The malware can escalate to steal sensitive data and provide long-term access to compromised systems.
The EtherHiding Attack Method
Attackers begin by compromising legitimate website addresses using a Loader Script. They then inject JavaScript code into the website. This code triggers a separate malicious package hidden within a smart contract. When a user interacts with the compromised site, the malware is activated, aiming to steal funds and data.
Evading Detection
Crucially, the compromised website communicates with the blockchain network using a "read-only" function. This allows threat actors to avoid creating actual transactions on the ledger, thereby evading detection and minimizing associated transaction fees, according to Google researchers.
Social Engineering Tactics
The EtherHiding campaign frequently targets software and cryptocurrency developers. Threat actors establish fake companies, recruitment agencies, and online profiles to present enticing fake employment offers. Communications are often moved to platforms like Discord or Telegram, where victims are prompted to complete coding tests or employment assessments.
Malware Deployment Stages
During the technical assessment phase, victims are typically instructed to download malicious files from code repositories like GitHub. In other scenarios, attackers may initiate a video call, display a fake error message, and prompt the user to download a software patch that contains the malicious code. Once installed, a second-stage JavaScript-based malware known as "JADESNOW" is deployed to exfiltrate sensitive data. For high-value targets, a third stage can grant attackers persistent access to the compromised machine and connected network systems.
Sources
-
North Korea Hackers Embed Sophisticated Code Exploit in Smart Contracts, Cointelegraph.
-
What is EtherHiding? Google flags malware with crypto-stealing code in smart contracts — TradingView News, TradingView.
This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.
