UNC5342
2025-04-24 • Mandiant • M-Trends 2025: Data, Insights, and Recommendation…
Google's Threat Intelligence Group documented the North Korea-linked cluster UNC5342 in an October 2025 report, describing its adoption, tracked since February 2025, of "EtherHiding" — storing and retrieving malicious payloads via read-only calls to smart contracts on public blockchains (BNB Smart Chain and Ethereum) — marking the first observed nation-state use of this technique. UNC5342 operates within a social-engineering campaign that Palo Alto Networks dubbed "Contagious Interview," using fake recruiters and fabricated companies to lure software and cryptocurrency developers with job offers, coding tests, and fake error-message prompts that trick victims into running malicious code. The infection chain uses the JADESNOW JavaScript downloader, which queries blockchain smart contracts to fetch a JavaScript variant of the INVISIBLEFERRET backdoor, enabling credential and cryptocurrency-wallet theft and remote access. A 2026 incident report aligning its findings with the Google-documented cluster described UNC5342 tradecraft expanding beyond job lures into a fake macOS software-update lure encountered through ordinary web browsing, deploying a backdoor, an infostealer, and a sideloaded malicious browser extension, backed by on-chain configuration contracts and exchange-funded wallet infrastructure.
-
28
Related Actors
-
4
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster