# UNC5342

> As of 2026-09-13, UNC5342 is a North Korea (DPRK)-nexus threat actor tracked by Threadlinqs Intelligence across 7 threats spanning threat intel, malware, supply chain. ATT&CK coverage spans 83 techniques across 13 tactics in 7 of 7 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1140 (Deobfuscate/Decode Files or Information), T1041 (Exfiltration Over C2 Channel).

- **Nation:** North Korea (DPRK)
- **Tracked threats:** 7
- **Categories:** THREAT_INTEL, MALWARE, SUPPLY_CHAIN, APT
- **As of:** 2026-09-13

## ATT&CK techniques observed

83 techniques observed across 7 of 7 tracked threats. Tactics: Command and Control (12), Resource Development (12), Stealth (formerly Defense Evasion) (10), Initial Access (9), Credential Access (8), Execution (8).

- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 7 of 7 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 6 of 7 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 5 of 7 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 4 of 7 tracked threats
- [T1059.007](https://intel.threadlinqs.com/technique/T1059.007) JavaScript — Execution — observed in 4 of 7 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 4 of 7 tracked threats
- [T1083](https://intel.threadlinqs.com/technique/T1083) File and Directory Discovery — Discovery — observed in 4 of 7 tracked threats
- [T1102](https://intel.threadlinqs.com/technique/T1102) Web Service — Command and Control — observed in 4 of 7 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 4 of 7 tracked threats
- [T1555.003](https://intel.threadlinqs.com/technique/T1555.003) Credentials from Web Browsers — Credential Access — observed in 4 of 7 tracked threats
- [T1567](https://intel.threadlinqs.com/technique/T1567) Exfiltration Over Web Service — Exfiltration — observed in 4 of 7 tracked threats
- [T1573](https://intel.threadlinqs.com/technique/T1573) Encrypted Channel — Command and Control — observed in 4 of 7 tracked threats
- [T1657](https://intel.threadlinqs.com/technique/T1657) Financial Theft — Impact — observed in 4 of 7 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 3 of 7 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 3 of 7 tracked threats

## Tracked threats

- [Blockchain-Based C2 Evolution: Nation-State Actors Adopt Smart-Contract C2 (EtherHiding, JADESNOW/INVISIBLEFERRET, SharkStealer)](https://intel.threadlinqs.com/threat/TL-2026-2484) — HIGH
- [ClickFix Campaign Uses EtherHiding to Deliver Node.js RAT, Infostealer, and Malicious Chrome Extension — DPRK Wallet Trail Exposed](https://intel.threadlinqs.com/threat/TL-2026-1800) — HIGH
- [North Korean UNC5342 EtherHiding Campaign: Node.js RAT Delivered via Fake macOS Update Lures Using Ethereum Smart-Contract C2](https://intel.threadlinqs.com/threat/TL-2026-1794) — HIGH
- [DPRK's UNC5342 Adopts EtherHiding to Deliver JADESNOW and INVISIBLEFERRET via Blockchain Smart Contracts](https://intel.threadlinqs.com/threat/TL-2026-1511) — HIGH
- [astro.config.mjs Supply Chain Attack via Blockchain Dead-Drop C2 (PolinRider / js.jadesnow)](https://intel.threadlinqs.com/threat/TL-2026-0846) — HIGH
- [Famous Chollima (DPRK) Compromises Packagist Package roberts/leads dev Branch — tailwind.js Node.js Loader Uses TRON/Aptos/BNB Blockchain Dead-Drop C2 (EtherHiding-style)](https://intel.threadlinqs.com/threat/TL-2026-0638) — HIGH
- [Void Dokkaebi (Contagious Interview / Famous Chollima) — DPRK Fake Job Interview Campaign Delivering BeaverTail, InvisibleFerret, OtterCookie & GolangGhost via Trojanized Code Repositories](https://intel.threadlinqs.com/threat/TL-2026-0402) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/UNC5342
