Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
What is EtherHiding? Google flags malware with crypto-stealing code in smart contracts

What is EtherHiding? Google flags malware with crypto-stealing code in smart contracts

CryptoNewsNetCryptoNewsNet2025/10/17 21:57
By:cointelegraph.com

North Korean hackers have adopted a method of deploying malware designed to steal crypto and sensitive information by embedding malicious code into smart contracts on public blockchain networks, according to Google’s Threat Intelligence Group.

The technique, called “EtherHiding,” emerged in 2023 and is typically used in conjunction with social engineering techniques, such as reaching out to victims with fake employment offers and high-profile interviews, directing users to malicious websites or links, according to Google.

Hackers will take control of a legitimate website address through a Loader Script and embed JavaScript code into the website, triggering a separate malicious code package in a smart contract designed to steal funds and data once the user interacts with the compromised site.

What is EtherHiding? Google flags malware with crypto-stealing code in smart contracts image 0
Simplified illustration of how the “EtherHiding” hack works. Source: Google Cloud

The compromised website will communicate with the blockchain network using a “read-only” function that does not actually create a transaction on the ledger, allowing the threat actors to avoid detection and minimize transaction fees, Google researchers said.

The report highlights the need for vigilance in the crypto community to keep users safe from scams and hacks commonly employed by threat actors attempting to steal funds and valuable information from individuals and organizations alike.

Related: CZ’s Google account targeted by ‘government-backed’ hackers

Know the signs: North Korea social engineering campaign decoded

The threat actors will set up fake companies, recruitment agencies and profiles to target software and cryptocurrency developers with fake employment offers, according to Google.

After the initial pitch, the attackers move the communication to messaging platforms like Discord or Telegram and direct the victim to take an employment test or complete a coding task.

“The core of the attack occurs during a technical assessment phase,” Google Threat Intelligence said. During this phase, the victim is typically told to download malicious files from online code repositories like GitHub, where the malicious payload is stored.

In other instances, the attackers lure the victim into a video call, where a fake error message is displayed to the user, prompting them to download a patch to fix the error. This software patch also contains malicious code.

Once the malicious software is installed on a machine, second-stage JavaScript-based malware called “JADESNOW” is deployed to steal sensitive data.

A third stage is sometimes deployed for high-value targets, allowing the attackers long-term access to a compromised machine and other systems connected to its network, Google warned.

Magazine: Inside a 30,000 phone bot farm stealing crypto airdrops from real users

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Bitcoin News Update: Bitcoin Surges Back to $90K—Is This a New Beginning or Just a Pause in the Bear Market?

- Bitcoin rebounded from $79,500 to $88,000 amid mid-sized wallet accumulation and ETF inflows, signaling potential market stabilization. - BlackRock ETF holders regained $3.2B profits as price reclaimed $90K, shifting institutional sentiment despite whale selling. - On-chain data shows mid-sized wallets (10–1,000 BTC) stabilizing prices, contrasting with whale outflows and leveraged futures liquidations. - Technical indicators cap Bitcoin below $105K EMAs, with $97K–$98K liquidity pocket as next critical

Bitget-RWA2025/11/30 09:50
Bitcoin News Update: Bitcoin Surges Back to $90K—Is This a New Beginning or Just a Pause in the Bear Market?

Visa’s Embrace of Blockchain Technology Updates the Worldwide Payment System

- Visa partners with Aquanow to expand stablecoin settlements in CEMEA, enabling faster cross-border payments via USDC and reducing operational costs. - The initiative scales to $2.5B monthly volume after a 2023 pilot, modernizing payment infrastructure by eliminating intermediaries and weekend delays. - Aquanow's institutional-grade crypto expertise supports Visa's digital asset ambitions, aligning with broader industry trends toward blockchain adoption. - While competitors like Mastercard advance stablec

Bitget-RWA2025/11/30 09:50
Visa’s Embrace of Blockchain Technology Updates the Worldwide Payment System

Uzbekistan’s 2026 Stablecoin Initiative Seeks Expansion While Enforcing Rigorous Regulation

- Uzbekistan will legalize stablecoin payments and tokenized securities under strict 2026 regulations, marking a shift from prior crypto restrictions. - A regulatory sandbox will test stablecoin systems and develop tokenized markets, aligning with its Digital Uzbekistan 2030 innovation strategy. - The central bank will oversee risks, requiring all crypto transactions to flow through licensed providers with mandatory customer identification since 2023. - This controlled approach aims to attract foreign inve

Bitget-RWA2025/11/30 09:50
Uzbekistan’s 2026 Stablecoin Initiative Seeks Expansion While Enforcing Rigorous Regulation

Bitcoin News Update: S&P 500 Maintains Its Criteria, Leaves Out Bitcoin-Focused MSTR

- S&P 500 excludes MSTR for third time, citing reliance on Bitcoin assets over operational revenue. - MSCI reviews crypto-heavy firms, proposing 50% asset threshold for benchmark removal to maintain sector balance. - Saylor defends MSTR's corporate identity but acknowledges financials resemble investment vehicles with minimal software revenue. - Index providers prioritize operational stability and profitability, contrasting MSTR's volatile Bitcoin-linked earnings and losses. - Market context shows S&P 500

Bitget-RWA2025/11/30 09:50
Bitcoin News Update: S&P 500 Maintains Its Criteria, Leaves Out Bitcoin-Focused MSTR