North Korean Hackers Use EtherHiding to Hide Malware Inside Blockchain Smart Contracts

Thursday, October 16, 2025 2:56 PM | The Hacker News
A threat actor with ties to the Democratic People's Republic of Korea (aka North Korea) has been observed leveraging the EtherHiding technique to distribute malware and enable cryptocurrency theft, marking the first time a state-sponsored hacking group has embraced the method. The activity has been attributed by Google Threat Intelligence Group (GTIG) to a threat cluster it tracks as UNC5342,