• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: North Korean Hackers Employ Blockchain for Malware Operations Targeting Job Seekers
Share
  • bitcoinBitcoin(BTC)$72,544.00
  • ethereumEthereum(ETH)$2,121.58
  • tetherTether(USDT)$1.00
  • binancecoinBNB(BNB)$691.43
  • rippleXRP(XRP)$1.51
  • usd-coinUSDC(USDC)$1.00
  • solanaSolana(SOL)$90.52
  • tronTRON(TRX)$0.282159
  • staked-etherLido Staked Ether(STETH)$2,260.93
  • dogecoinDogecoin(DOGE)$0.102644
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
News

North Korean Hackers Employ Blockchain for Malware Operations Targeting Job Seekers

News Desk
Last updated: October 17, 2025 11:13 am
News Desk
Published: October 17, 2025
Share
1760690180 image 1760690155499 optimized.webp

A newly surfaced report indicates that the North Korean hacking group known as Famous Chollima is utilizing advanced blockchain technology to distribute malware, marking a significant evolution in cyber warfare tactics. This method, identified as “EtherHiding,” enables the group to embed malicious payloads within smart contracts, thereby obscuring their operations from traditional detection methods.

Cisco Talos and Google Threat Intelligence Group released findings showing that the attacks predominantly target job seekers, luring them through bogus interview processes. The attackers deploy sophisticated malware that is engineered to steal cryptocurrency and sensitive credentials. Central to these operations is a newly developed JavaScript module that combines two potent forms of malware, BeaverTail and OtterCookie. This malware is equipped with keylogging and screenshot functionalities, further enhancing its capabilities.

The malware spreads via a Node.js package available on the official NPM repository, disguised as a seemingly harmless chess application named “Chessfi.” Research indicates that the UNC5342 group has been embedding various malware forms, including JADESNOW malware and INVISIBLEFERRET backdoors, within smart contracts on prominent blockchains such as the BNB Smart Chain and Ethereum since February 2025.

This emergent tactic of EtherHiding enables attackers to exploit public blockchains as decentralized command-and-control infrastructures that are difficult for law enforcement to dismantle. By storing malicious payloads within smart contracts, these hackers create a resilient framework that can be dynamically updated without triggering alarming transaction fees, thus evading typical monitoring mechanisms.

The revelation comes amid heightened scrutiny of North Korean cyber activities, with estimates suggesting the regime has siphoned over $1.3 billion through various cyber incidents throughout 2024 and an alarming $2.2 billion in just the first half of 2025. This stolen wealth is believed to be funneled into funding the country’s weapons programs via extensive money laundering networks.

EtherHiding specifically turns decentralized ledgers into durable hosting platforms for attackers. By embedding malicious JavaScript within smart contracts and retrieving them with read-only function calls, these cybercriminals avoid creating a visible record on the blockchain. The method facilitates anonymous transactions, allowing attackers to conceal their identities effectively.

Google Threat Intelligence noted the utilization of EtherHiding in the so-called “Contagious Interview” campaign, wherein fake recruiters impersonate renowned companies like Coinbase and Robinhood. As part of this scheme, potential victims are often encouraged to download malicious files during technical assessments, leading to multi-stage infections.

The JADESNOW downloader, once activated, utilizes API queries to the BNB Smart Chain to fetch payloads from a specific smart contract address. Analysis indicates this contract has undergone over 20 updates within a four-month span, with the average transaction costing approximately $1.37 in gas fees.

The on-chain transactions reveal Base64-encoded and XOR-encrypted messages that eventually decrypt into heavily obfuscated JavaScript payloads, indicating a complex and evolving strategy to pivot between different blockchain networks. The final payload from INVISIBLEFERRET.JAVASCRIPT aims to connect to command-and-control servers utilizing port 3306, capturing critical user information such as hostname, username, operating system, and current directory.

In a significant twist, North Korean operatives have been reported to establish legitimate U.S. corporations under fictitious identities to further enhance their credibility. One such front, Blocknovas, was registered to an abandoned lot in South Carolina, illustrating the lengths to which these hackers will go.

This trend of deception has been documented at least 25 times, involving North Korean IT workers masquerading under over 30 fake identities with phony government IDs and LinkedIn profiles. The leak of systematic expense documentation has revealed purchases of Social Security numbers, professional accounts, and VPN services.

In light of these developments, industry leaders remain vigilant. Changpeng Zhao, the founder of Binance, has identified critical attack vectors, emphasizing the need for heightened awareness concerning fraudulent job applications, malware-laden links, and various scams targeting crypto operations. The sophistication and creativity exhibited by these North Korean hackers signal an urgent need for robust defenses against emerging cyber threats.

The myth of the time-travel millionaire: a deep dive into Bitcoin’s volatile history and the realities of becoming a crypto millionaire
XRP Surges Past $2.40 Amid Major Developments Including David Schwartz’s New Role at Evernorth
Coinbase Global: Evaluating Growth Potential Amid Valuation Concerns
HBAR Faces Stagnation Amid Declining Volatility and Sideways Trading Pattern
Stephen King Praises Scott Cooper’s “Springsteen: Deliver Me from Nowhere” Amid Box Office Struggles
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article JXZT64HHFBLWDLM4VD2BZVVVTY Sterling Weakened as Investors Flee to Safe-Haven Currencies Amid Economic Uncertainty
Next Article 00b76920 a9ff 11f0 9ead 08edf0d25c3e Valuation Perspectives: Navigating Stock Selection Amid Market Uncertainties
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
JU4R54CY7RDNVH7BKSYS5O543Q
Treasury Secretary Bessent Says Government Cannot Bail Out Bitcoin Amidst Lawmaker Scrutiny
c91d6810 01fc 11f1 afee adf1da880027
Wall Street Struggles as AI Fears and Weak Jobs Data Weigh on Markets
GettyImages 2201668226 e1770234419289
IonQ Faces Scrutiny Over Revenue Integrity and Insider Sales Amid Short Seller Allegations
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Finance
  • News
  • Company
  • Stocks
  • Bitcoin
  • XRP
  • Ethereum
  • Altcoins
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?