#EtherHiding
Incident/Operation
2025-10-16 • DPRK Adopts EtherHiding: Nation-State Malware Hiding on Blockchains
EtherHiding is a malware-delivery and command-and-control technique that stores malicious configuration or payload material in public blockchain transactions, making the data difficult to remove or sinkhole. DPRK-linked activity has used wallet and transaction references to retrieve encoded, encrypted stages across multiple blockchains, including loaders delivered through trojanized npm packages and compromised developer configuration files. Observed chains executed in Node.js tooling and deployed backdoors capable of command execution, system profiling, persistent communications, and theft of files and credentials.
-
9
Tagged Reports
-
7
Unique Authors
-
291
Active Days