# DPRK's UNC5342 Adopts EtherHiding to Deliver JADESNOW and INVISIBLEFERRET via Blockchain Smart Contracts

> Google Threat Intelligence Group (GTIG) reports that North Korea-linked UNC5342, operating within the 'Contagious Interview' campaign active since February 2025, is the first observed nation-state actor to adopt EtherHiding — hosting malicious JavaScript payloads in BNB Smart Chain and Ethereum smart contracts and retrieving them via read-only eth_call requests to evade takedown.

- **Published:** 2026-07-19T00:00:00Z
- **Last reviewed:** 2026-07-19T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1511
- **ID:** TL-2026-1511
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** UNC5342 (North Korea)
- **Detections:** 9 · **IOCs:** 23 (full data via the Threadlinqs MCP server — Purple tier)

## Description

UNC5342, a North Korea (DPRK) state-sponsored threat cluster operating the long-running 'Contagious Interview' social-engineering campaign (also tracked as CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, Famous Chollima, Gwisin Gang, Tenacious Pungsan, and Void Dokka), has become the first nation-state actor observed adopting EtherHiding — a technique first documented in September/October 2023 by Guardio Labs against the financially motivated CLEARFAKE campaign run by UNC5142. EtherHiding embeds malicious JavaScript payloads inside smart contracts deployed on BNB Smart Chain and Ethereum, retrieved via read-only eth_call requests that create no visible transaction and incur no gas fees, giving attackers a decentralized, effectively unseizable hosting layer for C2 and payload delivery. UNC5342 lures software and cryptocurrency developers through fake recruiter personas on LinkedIn and job boards, impersonating shell companies (BlockNovas LLC, Angeloper Agency, SoftGlideLLC), moving the conversation to Telegram or Discord, and requesting a 'technical assessment' that requires the victim to clone and run a GitHub repository or npm package, or to fix a fake ClickFix video-call error by running attacker-supplied code. The resulting infection chain runs a JavaScript downloader (JADESNOW, evolved from the HexEval Loader lineage) that queries BNB Smart Chain/Ethereum smart contracts via eth_call, decodes Base64/XOR-encrypted payloads in memory, and drops the BEAVERTAIL JavaScript infostealer, which in turn deploys the INVISIBLEFERRET backdoor in both Python and JavaScript variants. BEAVERTAIL and INVISIBLEFERRET together harvest browser-stored credentials, session cookies, payment card data, and cryptocurrency wallet data (MetaMask, Phantom) plus password-manager vaults (1Password), compress the loot into ZIP archives, and exfiltrate it to attacker infrastructure and private Telegram chats. The JavaScript INVISIBLEFERRET variant additionally opens an interactive backdoor over TCP/3306 (masquerading as MySQL) supporting arbitrary command execution and file/directory exfiltration. UNC5342 has also folded this tooling into supply-chain operations, publishing malicious npm packages (including a June 2025 wave compromising React Native Aria/GlueStack-adjacent tooling and a subsequent wave of 35 typosquatted packages such as reactbootstraps and react-plaid-sdk) that pull JADESNOW/BEAVERTAIL at install time. On-chain, GTIG identified a primary BNB Smart Chain contract (0x8eac3198dd72f3e07108c4c7cff43108ad48a71c) updated 20+ times over four months at an average gas cost of $1.37 per update, owned by wallet 0x9bc1355344b54dedf3e44296916ed15653844509, and observed a parallel Ethereum-side 'dead drop resolver' technique (MITRE T1102.001) in which payload data is smuggled as transaction calldata sent to the null/burn address 0x000000000000000000000000000000000000dEaD, making the sender address itself irrelevant to retrieval. UNC5342 retrieves this data through centralized blockchain-explorer APIs (Binplorer, Blockchair, Blockcypher, Ethplorer) for redundancy, in contrast to UNC5142's direct RPC-node approach — a centralization dependency that gives defenders a practical intervention point despite the underlying blockchain's immutability. The campaign's dual objectives are cryptocurrency theft and espionage/persistent access against software and crypto-industry developers, and it remains active as of the October 2025 GTIG disclosure and subsequent 2026 reporting on continued front-company and npm-package waves.

## MITRE ATT&CK

- T1589 Gather Victim Identity Information
- T1585.001 Social Media Accounts
- T1583.006 Web Services
- T1195.002 Compromise Software Supply Chain
- T1566.002 Spearphishing Link
- T1566.001 Spearphishing Attachment
- T1195.001 Compromise Software Dependencies and Development Tools
- T1059.007 JavaScript
- T1059.006 Python
- T1204.002 Malicious File
- T1505 Server Software Component
- T1036 Masquerading
- T1140 Deobfuscate/Decode Files or Information
- T1027 Obfuscated Files or Information
- T1555.003 Credentials from Web Browsers
- T1539 Steal Web Session Cookie
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1005 Data from Local System
- T1560 Archive Collected Data
- T1102.001 Dead Drop Resolver
- T1105 Ingress Tool Transfer
- T1571 Non-Standard Port
- T1102 Web Service
- T1041 Exfiltration Over C2 Channel
- T1020 Automated Exfiltration
- T1567 Exfiltration Over Web Service
- T1657 Financial Theft

## Sources

- [DPRK adopts EtherHiding in a new nation state first](https://cloud.google.com/blog/topics/threat-intelligence/dprk-adopts-etherhiding/)
- [New Group on the Block: UNC5142 Leverages EtherHiding to Distribute Malware](https://cloud.google.com/blog/topics/threat-intelligence/unc5142-etherhiding-distribute-malware)
- [Contagious Interview: Malware delivered through fake developer job interviews](https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/)
- [Another Wave: North Korean Contagious Interview Campaign Drops 35 New Malicious npm Packages](https://socket.dev/blog/north-korean-contagious-interview-campaign-drops-35-new-malicious-npm-packages)
- [North Korea-linked Supply Chain Attack Targets Developers with 35 Malicious npm Packages](https://thehackernews.com/2025/06/north-korea-linked-supply-chain-attack.html)
- [New wave of 'fake interviews' use 35 npm packages to spread malware](https://www.bleepingcomputer.com/news/security/new-wave-of-fake-interviews-use-35-npm-packages-to-spread-malware/)
- [Tenacious Pungsan: A DPRK threat actor linked to Contagious Interview](https://securitylabs.datadoghq.com/articles/tenacious-pungsan-dprk-threat-actor-contagious-interview/)
- [BeaverTail Malware Resurfaces in Malicious npm Packages Targeting Developers](https://thehackernews.com/2024/10/beavertail-malware-resurfaces-in.html)
- [Contagious Interview (DPRK) Launches a New Campaign Creating Three Front Companies to Deliver a Trio of Malware: BeaverTail, InvisibleFerret, and OtterCookie](https://www.silentpush.com/blog/contagious-interview-front-companies/)
- [North Korean Hackers Deploy BeaverTail Malware via 11 Malicious npm Packages](https://thehackernews.com/2025/04/north-korean-hackers-deploy-beavertail.html)
- [Hackers Abuse Blockchain Smart Contracts to Spread Malware via Infected WordPress Sites](https://thehackernews.com/2025/10/hackers-abuse-blockchain-smart.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1511
