ClickFix, EtherHiding & a DPRK Wallet Trail

2026-07-29 Allsecure

https://www.allsecure.io/blog/clickfix-etherhiding-dprk-wallet

Thumbnail for ClickFix, EtherHiding & a DPRK Wallet Trail

A search-driven malvertising chain displayed a fake macOS update and used ClickFix instructions to make victims paste a Node.js backdoor command into Terminal. The implant retrieved rotating C2 configuration from Ethereum smart contracts, executed JavaScript tasks remotely, stole cryptocurrency-wallet, browser, developer, and cloud credentials, and sideloaded a malicious Chrome extension. AllSecure linked the backdoor, extension, disposable deployment wallets, and laundering paths to one operation matching DPRK-linked UNC5342 and the Contagious Interview campaign. The report identifies previously unreported C2 domains and Ethereum infrastructure associated with the activity.

Indicators of Compromise

Type Value First Seen Last Seen
WALLET 0x75ac1ebf164c6f2ac24e73bb4c951… 2026-07-29 2026-07-29
WALLET 0xdf16a4d0a234a2bbc4d21645d4c7a… 2026-07-29 2026-07-29
WALLET 0x89c5151236De544d077fC69813A4d… 2026-07-29 2026-07-29
WALLET 0x277765FB63601cE5A9814daf68aA2… 2026-07-29 2026-07-29
WALLET 0x85a6d913aaC80286f01Fa082ef0B9… 2026-07-29 2026-07-29
WALLET 0x2acA749b59529f5CBCd6fbd34B35b… 2026-07-29 2026-07-29
URL https://th-updates.sbs/analytics 2026-07-29 2026-07-29
URL https://rg-telemetry.sbs/api 2026-07-29 2026-07-29
URL https://real-tumble.pro/zpXxnS8… 2026-07-29 2026-07-29
DOMAIN th-updates.sbs 2026-07-29 2026-07-29
DOMAIN rg-telemetry.sbs 2026-07-29 2026-07-29
DOMAIN real-tumble.pro 2026-07-29 2026-07-29

Related Actors

Related Reports

« Back