# North Korean UNC5342 EtherHiding Campaign: Node.js RAT Delivered via Fake macOS Update Lures Using Ethereum Smart-Contract C2

> DPRK-linked UNC5342 (Contagious Interview) is running a macOS malvertising campaign that uses ClickFix-style fake update overlays to deliver a Node.js RAT, a 157-wallet infostealer, and a malicious Chrome MV3 extension disguised as 'Google Drive Offline'. The malware resolves its C2 by querying Ethereum smart contracts (EtherHiding) instead of a fixed server, and the operation has moved roughly $890,000 in ETH through attacker wallets between late May and July 2026.

- **Published:** 2026-07-31T00:00:00Z
- **Last reviewed:** 2026-07-31T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1794
- **ID:** TL-2026-1794
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** UNC5342 (North Korea)
- **Detections:** 9 · **IOCs:** 29 (full data via the Threadlinqs MCP server — Purple tier)

## Description

In July 2026, security firm AllSecure identified a malvertising campaign delivering macOS malware through fake browser/OS "update required" overlays. Victims arriving from search-ad traffic (observed lures included searches unrelated to security, e.g. laboratory-equipment queries) are shown a full-screen fake reboot/update sequence that silently copies an attacker-controlled shell command to the clipboard and instructs the victim to paste it into Terminal — the ClickFix social-engineering technique. Executing the command installs a Node.js-based backdoor (v1.0.3) that persists via a LaunchAgent and modified shell profile, and polls a hardcoded Ethereum JSON-RPC endpoint (and, per the wider UNC5342 tooling, centralized blockchain-explorer APIs) roughly every 5 minutes to read live C2 instructions written into a smart contract's calldata — the 'EtherHiding' dead-drop-resolver technique. Two follow-on payloads are staged: an infostealer module that harvests credentials/session data from Chrome, Brave, Edge, Firefox, Opera and Vivaldi plus SSH keys, AWS/Azure tokens, npm auth tokens and Foundry keystores, and targets 157 distinct cryptocurrency wallet formats; and a malicious Chrome extension masquerading as 'Google Drive Offline', sideloaded by directly patching Chrome's Secure Preferences file (bypassing the normal extension-integrity check) and used to drain browser-based crypto wallets. 

Google's Threat Intelligence Group (GTIG) first documented UNC5342's adoption of EtherHiding in October 2025, tracing the technique's origin to the financially motivated CLEARFAKE operator UNC5142 (first seen September 2023) and UNC5342's incorporation of it into the long-running 'Contagious Interview' social-engineering campaign since February 2025. UNC5342 (aka CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, Famous Chollima, Gwisin Gang, Tenacious Pungsan, Void Dokkaebi) primarily lures software/crypto developers with fake recruiter outreach and coding-test assessments that drop the BEAVERTAIL infostealer and JADESNOW downloader, which in turn uses EtherHiding to fetch the INVISIBLEFERRET backdoor (Python and JavaScript variants) from BNB Smart Chain and Ethereum smart contracts. The July 2026 fake-macOS-update wave expands this playbook from targeted developer recruitment to broad malvertising, and reuses the same EtherHiding C2 model with two dedicated configuration contracts (one for the backdoor, one for the extension), a hardcoded Ethereum RPC endpoint, and industrialized wallet-funding automation (fund ~0.0126 ETH, deploy contract, write config, forward remnants, abandon wallet) that produced 281 tracked transactions and ~464.80 ETH (~$890K) moved to attacker treasury wallets between late May and July 2026. GTIG and follow-on reporting note UNC5342's dual objective of cryptocurrency theft (partly to evade international sanctions) and espionage access to developer/corporate credentials, and flag that despite blockchain immutability, the actor's reliance on centralized blockchain-explorer APIs (Ethplorer, Blockchair, Binplorer, Blockcypher) and hardcoded RPC endpoints remains an observable, disruptable point of control.

## MITRE ATT&CK

- T1598 Phishing for Information
- T1583 Acquire Infrastructure
- T1587 Develop Capabilities
- T1566 Phishing
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1543 Create or Modify System Process
- T1546 Event Triggered Execution
- T1027 Obfuscated Files or Information
- T1036 Masquerading
- T1564 Hide Artifacts
- T1685 Disable or Modify Tools
- T1555 Credentials from Password Stores
- T1552 Unsecured Credentials
- T1539 Steal Web Session Cookie
- T1217 Browser Information Discovery
- T1082 System Information Discovery
- T1119 Automated Collection
- T1005 Data from Local System
- T1567 Exfiltration Over Web Service
- T1537 Transfer Data to Cloud Account
- T1102 Web Service
- T1573 Encrypted Channel
- T1071 Application Layer Protocol

## Sources

- [North Korean EtherHiding Campaign](https://cybersecuritynews.com/north-korean-etherhiding-campaign/)
- [DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware](https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html)
- [ClickFix, EtherHiding & a DPRK Wallet Trail](https://www.allsecure.io/blog/clickfix-etherhiding-dprk-wallet/)
- [DPRK Adopts EtherHiding: Nation-State Malware Hiding on Blockchains](https://cloud.google.com/blog/topics/threat-intelligence/dprk-adopts-etherhiding)
- [North Korean Hackers Use EtherHiding to Hide Malware Inside Blockchain Smart Contracts](https://thehackernews.com/2025/10/north-korean-hackers-use-etherhiding-to.html)
- [New Group on the Block: UNC5142 Leverages EtherHiding to Distribute Malware](https://cloud.google.com/blog/topics/threat-intelligence/unc5142-etherhiding-distribute-malware)
- [North Korean hackers use EtherHiding to hide malware on the blockchain](https://www.bleepingcomputer.com/news/security/north-korean-hackers-use-etherhiding-to-hide-malware-on-the-blockchain/)
- [North Korean threat actors turn blockchains into malware delivery servers](https://www.csoonline.com/article/4074916/north-korean-threat-actors-turn-blockchains-into-malware-delivery-servers.html)
- [North Korea's Contagious Interview Campaign](https://socket.dev/supply-chain-attacks/north-korea-s-contagious-interview-campaign)
- [RustDoor and Koi Stealer for macOS Used by North Korea-Linked Threat Actor to Target the Cryptocurrency Sector](https://unit42.paloaltonetworks.com/macos-malware-targets-crypto-sector/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1794
