ClickFix Campaign Uses EtherHiding to Deliver Node.js RAT, Infostealer, and Malicious Chrome Extension — DPRK Wallet Trail Exposed — Threadlinqs Intelligence
As of 2026-07-31, ClickFix Campaign Uses EtherHiding to Deliver Node.js RAT, Infostealer, and Malicious Chrome Extension — DPRK Wallet Trail Exposed is a high-severity malware threat attributed to UNC5342 (North Korea (DPRK)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 26 indicators of compromise.
Threat ID: TL-2026-1800 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: UNC5342 · North Korea (DPRK) · FINANCIAL
A DPRK-linked ClickFix campaign impersonates a frozen macOS 'Installing System Update' screen to trick victims into pasting a clipboard-hijacked command into Terminal, which deploys a Node.js RAT
This campaign combines the ClickFix social-engineering technique with EtherHiding, a blockchain-based command-and-control method first documented by Google Threat Intelligence Group (GTIG) in October 2025 as a tool of the DPRK threat cluster UNC5342 (aka CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, Famous Chollima, Gwisin Gang, Tenacious Pungsan, Void Dokkaebi), operating under the broader 'Contagious Interview' umbrella publicly tracked since February 2025.
Victims land on the lure — reported delivery paths include malvertising via sponsored search results (e.g., decoy 'electrophoresis machine' product searches) — and are shown a full-screen, browser-rendered fake macOS 'Installing System Update / reboot' overlay that locks out normal interaction. Before the victim can act, the page silently copies a base64-encoded attack command to the clipboard and instructs the user to open Terminal and paste it (the ClickFix pattern, MITRE T1204.004). Executing the pasted command (via curl) fetches next-stage malware from the delivery domain real-tumble.pro.
The payload is a ~38KB obfuscated Node.js backdoor (v1.0.3) that establishes persistence via a per-victim LaunchAgent (~/Library/LaunchAgents/com.<random>.plist), a modified .zshrc shell profile, and hidden staging files under ~/Library/Caches/<random> and /tmp/<random>. To resolve its C2 endpoint, the implant performs read-only eth_call requests across roughly 20 public Ethereum RPC endpoints against a smart contract (0x2acA749b59529f5CBCd6fbd34B35b1A546713dF6), invoking a getter function (selector 0x3bc5de30) that returns a base64 blob the implant XOR-decodes (key 9f10d0899beff7952f586a49305f8b14) into a {url, key} C2 definition currently pointing at https://rg-telemetry.sbs/api. The backdoor beacons roughly every 5 minutes, executes attacker-supplied JavaScript via eval(), and returns output over an encrypted channel — giving the operator arbitrary remote code execution with no conventional, seizable C2 server to take down.
A second-stage infostealer module harvests data from Chrome, Brave, Edge, Firefox, Opera, and Vivaldi (saved passwords, cookies, autofill/payment data), 157 desktop and browser-extension cryptocurrency wallets (including MetaMask- and Phantom-class wallets), SSH private keys, AWS and Azure credentials, npm registry tokens, and Foundry (Ethereum dev tooling) keystores — a target list clearly aimed at developer and crypto-operator machines.
A malicious Chrome MV3 extension disguised as 'Google Drive Offline' is sideloaded by directly patching Chrome's Secure Preferences file (bypassing the normal extension-installation UI/consent flow), giving the operator persistent browser access to drain wallets and intercept session data. It resolves its own C2 (https://th-updates.sbs/analytics) via a second EtherHiding contract (0x85a6d913aaC80286f01Fa082ef0B96C188673043, XOR key 2752df77aeb348657f5fb59a22d65f4a) using the same read-only eth_call/getter pattern.
On-chain analysis of the attacker's Ethereum treasury shows funder wallets 0x277765FB63601cE5A9814daf68aA2A57F54eA968 and 0x89c5151236De544d077fC69813A4db89224EE8A1 feeding treasury wallets 0xdf16a4d0a234a2bbc4d21645d4c7a19d2db8f192 and 0x75ac1ebf164c6f2ac24e73bb4c9518b8d93559e2. Separately, researchers traced the KuCoin '17' hot wallet (0x45300136662dd4e58fc0df61e6290dffd992b785) sending 464.80 ETH (~$890,000) across 281 transfers between 28 May and 30 July 2026 into this network with nothing returned — roughly 45% of everything the treasury received before being drained, and part of a broader ~$1.96M movement over nine weeks. A related funding leg was seeded from Binance USDT withdrawals into a laundering cluster publicly tagged by block explorers as 'Fake_Phishing2114928', which is saturated with address-poisoning spam (homoglyph DAI impostor contracts, zero-value transfers, lookalike addresses) consistent with DPRK laundering tradecraft.
This activity extends UNC5342's toolkit beyond the JADESNOW (JavaScri
Target sectors: cryptocurrency, financial-services, technology, software-development
Target regions: Global
Detections & IOCs
As of 2026-08-04, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 26 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583.001, T1583.008, T1587.001, T1608.001, T1189, T1204.004, T1059.007, T1059.004, T1543.001, T1546.004