Threat reportMalwareTL-2026-1794

North Korean UNC5342 EtherHiding Campaign: Node.js RAT Delivered via Fake macOS Update Lures Using Ethereum Smart-Contract C2

highACTIVE

North Korean UNC5342 EtherHiding Campaign (TL-2026-1794), also tracked as EtherHiding Campaign, is a high-severity malware campaign, first published 2026-07-31. It is attributed to UNC5342 (North Korea) with high confidence, affects Apple macOS, maps to 24 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 29 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
24MITRE ATT&CK
Actors
1UNC5342
Detection rules
9SPL · KQL · Sigma
IOCs
29Indicators of compromise

Key facts for TL-2026-1794

Threat ID
TL-2026-1794
Also known as
EtherHiding Campaign, ClickFix EtherHiding DPRK Wallet Trail
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
UNC5342
Attribution confidence
HIGH
Nation-state nexus
North Korea
Motivation
FINANCIAL
Target sectors
cryptocurrency, technology, software development, financial services, web3 defi
Target regions
Global
Detection rules
9
Indicators of compromise
29

Malware and tooling in North Korean UNC5342 EtherHiding Campaign

Malware and tooling: BeaverTail - S1246, InvisibleFerret - S1245, JADESNOW, LUMASTEALER, Blockchair, Ethplorer

How North Korean UNC5342 EtherHiding Campaign works

DPRK-linked UNC5342 (Contagious Interview) is running a macOS malvertising campaign that uses ClickFix-style fake update overlays to deliver a Node.js RAT, a 157-wallet infostealer, and a malicious Chrome MV3 extension disguised as 'Google Drive Offline'. The malware resolves its C2 by querying Ethereum smart contracts (EtherHiding) instead of a fixed server, and the operation has moved roughly $890,000 in ETH through attacker wallets between late May and July 2026.

In July 2026, security firm AllSecure identified a malvertising campaign delivering macOS malware through fake browser/OS "update required" overlays. Victims arriving from search-ad traffic (observed lures included searches unrelated to security, e.g. laboratory-equipment queries) are shown a full-screen fake reboot/update sequence that silently copies an attacker-controlled shell command to the clipboard and instructs the victim to paste it into Terminal — the ClickFix social-engineering technique. Executing the command installs a Node.js-based backdoor (v1.0.3) that persists via a LaunchAgent and modified shell profile, and polls a hardcoded Ethereum JSON-RPC endpoint (and, per the wider UNC5342 tooling, centralized blockchain-explorer APIs) roughly every 5 minutes to read live C2 instructions written into a smart contract's calldata — the 'EtherHiding' dead-drop-resolver technique. Two follow-on payloads are staged: an infostealer module that harvests credentials/session data from Chrome, Brave, Edge, Firefox, Opera and Vivaldi plus SSH keys, AWS/Azure tokens, npm auth tokens and Foundry keystores, and targets 157 distinct cryptocurrency wallet formats; and a malicious Chrome extension masquerading as 'Google Drive Offline', sideloaded by directly patching Chrome's Secure Preferences file (bypassing the normal extension-integrity check) and used to drain browser-based crypto wallets.

Google's Threat Intelligence Group (GTIG) first documented UNC5342's adoption of EtherHiding in October 2025, tracing the technique's origin to the financially motivated CLEARFAKE operator UNC5142 (first seen September 2023) and UNC5342's incorporation of it into the long-running 'Contagious Interview' social-engineering campaign since February 2025. UNC5342 (aka CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, Famous Chollima, Gwisin Gang, Tenacious Pungsan, Void Dokkaebi) primarily lures software/crypto developers with fake recruiter outreach and coding-test assessments that drop the BEAVERTAIL infostealer and JADESNOW downloader, which in turn uses EtherHiding to fetch the INVISIBLEFERRET backdoor (Python and JavaScript variants) from BNB Smart Chain and Ethereum smart contracts. The July 2026 fake-macOS-update wave expands this playbook from targeted developer recruitment to broad malvertising, and reuses the same EtherHiding C2 model with two dedicated configuration contracts (one for the backdoor, one for the extension), a hardcoded Ethereum RPC endpoint, and industrialized wallet-funding automation (fund ~0.0126 ETH, deploy contract, write config, forward remnants, abandon wallet) that produced 281 tracked transactions and ~464.80 ETH (~$890K) moved to attacker treasury wallets between late May and July 2026. GTIG and follow-on reporting note UNC5342's dual objective of cryptocurrency theft (partly to evade international sanctions) and espionage access to developer/corporate credentials, and flag that despite blockchain immutability, the actor's reliance on centralized blockchain-explorer APIs (Ethplorer, Blockchair, Binplorer, Blockcypher) and hardcoded RPC endpoints remains an observable, disruptable point of control.

MITRE ATT&CK techniques used in TL-2026-1794

Collection

T1005 Data from Local System; T1119 Automated Collection

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1564 Hide Artifacts

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071 Application Layer Protocol; T1102 Web Service; T1573 Encrypted Channel

Discovery

T1082 System Information Discovery; T1217 Browser Information Discovery

execution

T1204 User Execution

Exfiltration

T1537 Transfer Data to Cloud Account; T1567 Exfiltration Over Web Service

Credential Access

T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores

Persistence

T1543 Create or Modify System Process; T1546 Event Triggered Execution

Initial Access

T1566 Phishing

Resource Development

T1583 Acquire Infrastructure; T1587 Develop Capabilities

Reconnaissance

T1598 Phishing for Information

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in North Korean UNC5342 EtherHiding Campaign

  • Apple — macOS
    Vulnerable versions: All versions (social-engineering delivery vector via Terminal, not a software vulnerability)
  • Google — Google Chrome / Chromium-based browsers (Manifest V3 extensions)
    Vulnerable versions: All versions supporting Secure Preferences-based extension sideloading
  • Various — Cryptocurrency wallets (157 targeted formats, including MetaMask and Phantom)
    Vulnerable versions: Browser-extension and local-storage based wallets accessible from an infected profile

Remediation for North Korean UNC5342 EtherHiding Campaign

Immediate actions

  • Immediately isolate any macOS device where a user pasted and executed a clipboard command from a browser 'update' prompt
  • Inspect for unauthorized LaunchAgent plists (~/Library/LaunchAgents/com.<random>.plist), appended .zshrc entries, and hidden Node.js processes running from ~/Library/Caches/<random> or /tmp/<random>
  • Remove the 'Google Drive Offline' extension and any other unrecognized sideloaded extension; restore Chrome's Secure Preferences file from a known-good backup or reinstall the browser profile
  • Block C2 domains rg-telemetry.sbs and th-updates.sbs, delivery domain real-tumble.pro, and the hardcoded eth-mainnet.rpcfast.com API-key endpoint at DNS/perimeter
  • Rotate every credential type this malware targets: SSH keys, AWS/Azure tokens, npm auth tokens, Foundry keystores, and browser-saved passwords, from a clean device
  • Move any cryptocurrency held in wallets that were accessible on the affected device to newly generated wallets on a clean device

Workarounds

  • Enforce OS/browser updates exclusively through MDM-managed channels so no legitimate update prompt ever appears in-browser
  • Restrict interactive Terminal.app execution via endpoint policy for non-technical/developer-adjacent users where feasible

Longer-term hardening

  • Deploy EDR behavioral detections for LaunchAgent creation, shell-profile modification, and unsigned Node.js binaries launched from cache/temp directories
  • Enforce Chrome Enterprise policy to block unmanaged extension installs and detect Secure Preferences tampering
  • Monitor outbound traffic for blockchain-explorer API calls (Ethplorer, Blockchair, Binplorer, Blockcypher) and direct eth_call/JSON-RPC traffic as an EtherHiding C2 detection signal
  • Run recurring user-awareness training that legitimate OS/browser updates never require copying and pasting a Terminal command (ClickFix indicator)
  • For developer/crypto organizations, extend detection to the broader Contagious Interview kill chain (BEAVERTAIL/JADESNOW/INVISIBLEFERRET) delivered via fake recruiter and coding-test lures, not just this malvertising variant

Timeline of North Korean UNC5342 EtherHiding Campaign

  • EtherHiding technique first observed in the wild, used by financially-motivated CLEARFAKE operator UNC5142 to store fake-browser-update payloads in BNB Smart Chain smart contracts.
  • Google GTIG begins tracking DPRK-linked UNC5342 incorporating EtherHiding into its ongoing 'Contagious Interview' social-engineering operations.
  • UNC5342 activity linked to a malicious npm supply-chain attack affecting the React Native Aria and GlueStack packages, using the same EtherHiding smart contract infrastructure.
  • Google Threat Intelligence Group publishes 'DPRK Adopts EtherHiding', the first public attribution of blockchain-based C2 to a nation-state actor (UNC5342).
  • Tracked attacker treasury wallets begin receiving the ETH transfers later attributed to this fake-macOS-update campaign wave.
  • Approximately 464.80 ETH (~$890,000) confirmed transferred to attacker treasury wallets across 281 transactions between late May and July 2026.
  • AllSecure analysts identify the fake macOS update / Node.js RAT / 'Google Drive Offline' extension chain during investigation of a malvertising incident.
  • Cyber Security News and The Hacker News publish corroborating reporting attributing the campaign to UNC5342/Contagious Interview.
  • AllSecure publishes 'ClickFix, EtherHiding & a DPRK Wallet Trail', detailing the malware hashes, smart-contract addresses, and wallet-funding pattern.

Sources cited for North Korean UNC5342 EtherHiding Campaign

Detection coverage for TL-2026-1794

As of 2026-07-31, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1794 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
29 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats