ClickFix, EtherHiding & a DPRK Wallet Trail
2026-07-29 • Allsecure •
https://www.allsecure.io/blog/clickfix-etherhiding-dprk-wallet
A search-driven malvertising chain displayed a fake macOS update and used ClickFix instructions to make victims paste a Node.js backdoor command into Terminal. The implant retrieved rotating C2 configuration from Ethereum smart contracts, executed JavaScript tasks remotely, stole cryptocurrency-wallet, browser, developer, and cloud credentials, and sideloaded a malicious Chrome extension. AllSecure linked the backdoor, extension, disposable deployment wallets, and laundering paths to one operation matching DPRK-linked UNC5342 and the Contagious Interview campaign. The report identifies previously unreported C2 domains and Ethereum infrastructure associated with the activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| WALLET | 0x75ac1ebf164c6f2ac24e73bb4c951… | 2026-07-29 | 2026-07-29 |
| WALLET | 0xdf16a4d0a234a2bbc4d21645d4c7a… | 2026-07-29 | 2026-07-29 |
| WALLET | 0x89c5151236De544d077fC69813A4d… | 2026-07-29 | 2026-07-29 |
| WALLET | 0x277765FB63601cE5A9814daf68aA2… | 2026-07-29 | 2026-07-29 |
| WALLET | 0x85a6d913aaC80286f01Fa082ef0B9… | 2026-07-29 | 2026-07-29 |
| WALLET | 0x2acA749b59529f5CBCd6fbd34B35b… | 2026-07-29 | 2026-07-29 |
| URL | https://th-updates.sbs/analytics | 2026-07-29 | 2026-07-29 |
| URL | https://rg-telemetry.sbs/api | 2026-07-29 | 2026-07-29 |
| URL | https://real-tumble.pro/zpXxnS8… | 2026-07-29 | 2026-07-29 |
| DOMAIN | th-updates.sbs | 2026-07-29 | 2026-07-29 |
| DOMAIN | rg-telemetry.sbs | 2026-07-29 | 2026-07-29 |
| DOMAIN | real-tumble.pro | 2026-07-29 | 2026-07-29 |