ClickFix Campaign Uses EtherHiding to Deliver Node.js RAT, Infostealer, and Malicious Chrome Extension — DPRK Wallet Trail Exposed — Threadlinqs Intelligence
As of 2026-07-31, ClickFix Campaign Uses EtherHiding to Deliver Node.js RAT, Infostealer, and Malicious Chrome Extension — DPRK Wallet Trail Exposed is a high-severity malware threat attributed to UNC5342 (North Korea (DPRK)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 26 indicators of compromise.
Threat ID: TL-2026-1800 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: UNC5342 · North Korea (DPRK) · FINANCIAL
A DPRK-linked ClickFix campaign impersonates a frozen macOS 'Installing System Update' screen to trick victims into pasting a clipboard-hijacked command into Terminal, which deploys a Node.js RAT
This campaign combines the ClickFix social-engineering technique with EtherHiding, a blockchain-based command-and-control method first documented by Google Threat Intelligence Group (GTIG) in October 2025 as a tool of the DPRK threat cluster UNC5342 (aka CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, Famous Chollima, Gwisin Gang, Tenacious Pungsan, Void Dokkaebi), operating under the broader 'Contagious Interview' umbrella publicly tracked since February 2025.
Victims land on the lure — reported delivery paths include malvertising via sponsored search results (e.g., decoy 'electrophoresis machine' product searches) — and are shown a full-screen, browser-rendered fake macOS 'Installing System Update / reboot' overlay that locks out normal interaction. Before the victim can act, the page silently copies a base64-encoded attack command to the clipboard and instructs the user to open Terminal and paste it (the ClickFix pattern, MITRE T1204.004). Executing the pasted command (via curl) fetches next-stage malware from the delivery domain real-tumble.pro.
The payload is a ~38KB obfuscated Node.js backdoor (v1.0.3) that establishes persistence via a per-victim LaunchAgent (~/Library/LaunchAgents/com.<random>.plist), a modified .zshrc shell profile, and hidden staging files under ~/Library/Caches/<random> and /tmp/<random>. To resolve its C2 endpoint, the implant performs read-only eth_call requests across roughly 20 public Ethereum RPC endpoints against a smart contract (0x2acA749b59529f5CBCd6fbd34B35b1A546713dF6), invoking a getter function (selector 0x3bc5de30) that returns a base64 blob the implant XOR-decodes (key 9f10d0899beff7952f586a49305f8b14) into a {url, key} C2 definition currently pointing at https://rg-telemetry.sbs/api. The backdoor beacons roughly every 5 minutes, executes attacker-supplied JavaScript via eval(), and returns output over an encrypted channel — giving the operator arbitrary remote code execution with no conventional, seizable C2 server to take down.
A second-stage infostealer module harvests data from Chrome, Brave, Edge, Firefox, Opera, and Vivaldi (saved passwords, cookies, autofill/payment data), 157 desktop and browser-extension cryptocurrency wallets (including MetaMask- and Phantom-class wallets), SSH private keys, AWS and Azure credentials, npm registry tokens, and Foundry (Ethereum dev tooling) keystores — a target list clearly aimed at developer and crypto-operator machines.
A malicious Chrome MV3 extension disguised as 'Google Drive Offline' is sideloaded by directly patching Chrome's Secure Preferences file (bypassing the normal extension-installation UI/consent flow), giving the operator persistent browser access to drain wallets and intercept session data. It resolves its own C2 (https://th-updates.sbs/analytics) via a second EtherHiding contract (0x85a6d913aaC80286f01Fa082ef0B96C188673043, XOR key 2752df77aeb348657f5fb59a22d65f4a) using the same read-only eth_call/getter pattern.
On-chain analysis of the attacker's Ethereum treasury shows funder wallets 0x277765FB63601cE5A9814daf68aA2A57F54eA968 and 0x89c5151236De544d077fC69813A4db89224EE8A1 feeding treasury wallets 0xdf16a4d0a234a2bbc4d21645d4c7a19d2db8f192 and 0x75ac1ebf164c6f2ac24e73bb4c9518b8d93559e2. Separately, researchers traced the KuCoin '17' hot wallet (0x45300136662dd4e58fc0df61e6290dffd992b785) sending 464.80 ETH (~$890,000) across 281 transfers between 28 May and 30 July 2026 into this network with nothing returned — roughly 45% of everything the treasury received before being drained, and part of a broader ~$1.96M movement over nine weeks. A related funding leg was seeded from Binance USDT withdrawals into a laundering cluster publicly tagged by block explorers as 'Fake_Phishing2114928', which is saturated with address-poisoning spam (homoglyph DAI impostor contracts, zero-value transfers, lookalike addresses) consistent with DPRK laundering tradecraft.
This activity extends UNC5342's toolkit beyond the JADESNOW (JavaScri
Target sectors: cryptocurrency, financial-services, technology, software-development
Target regions: Global
Timeline
- Google Threat Intelligence Group observes DPRK cluster UNC5342 begin employing EtherHiding within Contagious Interview operations, the first documented nation-state use of the technique.
- Per GTIG's original disclosure, UNC5342's early EtherHiding smart contracts were updated over 20 times within four months at an average gas cost of ~$1.37 per update, demonstrating the operational agility of blockchain-hosted C2 later reused in this campaign's infrastructure.
- Google Threat Intelligence Group publicly discloses the EtherHiding technique and attributes it to DPRK threat cluster UNC5342, detailing the JADESNOW/INVISIBLEFERRET/BEAVERTAIL toolchain.
- Microsoft Security publishes research on a related ClickFix campaign using fake macOS utility lures to deliver infostealers, consistent with the broader DPRK ClickFix pivot toward macOS targeting.
- First of 281 tracked transfers begins moving from the KuCoin '17' hot wallet (0x45300136662dd4e58fc0df61e6290dffd992b785) into the attacker-controlled treasury network.
- Tracing concludes that 464.80 ETH (~$890,000) moved across 281 transfers since 28 May 2026 — roughly 45% of everything the treasury received — with none of it returned, as part of a broader ~$1.96M movement over nine weeks.
- AllSecure researchers publish the original technical analysis tying this ClickFix/EtherHiding campaign's Node.js RAT and Chrome extension infrastructure to the DPRK on-chain wallet trail.
- The Hacker News reports on the DPRK-linked macOS malvertising campaign delivering the Node.js backdoor, 157-wallet infostealer, and 'Google Drive Offline' malicious extension.
- GBHackers publishes coverage of the campaign, summarizing the EtherHiding C2 mechanics and the exposed DPRK wallet trail.
Detections & IOCs
As of 2026-09-04, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 26 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583.001, T1583.008, T1587.001, T1608.001, T1189, T1204.004, T1059.007, T1059.004, T1543.001, T1546.004