Bitget App
Trade smarter
Open
HomepageSign up
Bitget>
News>
Markets>
What is EtherHiding? Google flags malware with crypto-stealing code in smart contracts

What is EtherHiding? Google flags malware with crypto-stealing code in smart contracts

CryptoNewsNet2025/10/17 21:57
By: cointelegraph.com
CLOUD0.00%

North Korean hackers have adopted a method of deploying malware designed to steal crypto and sensitive information by embedding malicious code into smart contracts on public blockchain networks, according to Google’s Threat Intelligence Group.

The technique, called “EtherHiding,” emerged in 2023 and is typically used in conjunction with social engineering techniques, such as reaching out to victims with fake employment offers and high-profile interviews, directing users to malicious websites or links, according to Google.

Hackers will take control of a legitimate website address through a Loader Script and embed JavaScript code into the website, triggering a separate malicious code package in a smart contract designed to steal funds and data once the user interacts with the compromised site.

What is EtherHiding? Google flags malware with crypto-stealing code in smart contracts image 0
Simplified illustration of how the “EtherHiding” hack works. Source: Google Cloud

The compromised website will communicate with the blockchain network using a “read-only” function that does not actually create a transaction on the ledger, allowing the threat actors to avoid detection and minimize transaction fees, Google researchers said.

The report highlights the need for vigilance in the crypto community to keep users safe from scams and hacks commonly employed by threat actors attempting to steal funds and valuable information from individuals and organizations alike.

Related: CZ’s Google account targeted by ‘government-backed’ hackers

Know the signs: North Korea social engineering campaign decoded

The threat actors will set up fake companies, recruitment agencies and profiles to target software and cryptocurrency developers with fake employment offers, according to Google.

After the initial pitch, the attackers move the communication to messaging platforms like Discord or Telegram and direct the victim to take an employment test or complete a coding task.

“The core of the attack occurs during a technical assessment phase,” Google Threat Intelligence said. During this phase, the victim is typically told to download malicious files from online code repositories like GitHub, where the malicious payload is stored.

In other instances, the attackers lure the victim into a video call, where a fake error message is displayed to the user, prompting them to download a patch to fix the error. This software patch also contains malicious code.

Once the malicious software is installed on a machine, second-stage JavaScript-based malware called “JADESNOW” is deployed to steal sensitive data.

A third stage is sometimes deployed for high-value targets, allowing the attackers long-term access to a compromised machine and other systems connected to its network, Google warned.

Magazine: Inside a 30,000 phone bot farm stealing crypto airdrops from real users

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Dogecoin Getting Crushed as Market Fear Spreads
TheCryptoUpdates2025/10/18 16:36
ORDI Surges 163.27% Within 24 Hours Despite Recent Market Fluctuations

- ORDI surged 163.27% in 24 hours on Oct 17, 2025, contrasting with 18.99% declines across 7-day, 30-day, and 12-month metrics. - The sharp rise occurred without official catalysts, suggesting algorithmic trading or coordinated buying amid heightened volatility typical of small-cap crypto assets. - A proposed backtesting strategy analyzes historical ≥5% daily gains since 2022 to assess patterns, requiring precise ticker symbols for accurate execution. - Persistent 18.99% declines across multiple timeframes

Bitget-RWA2025/10/18 16:14

Trending news

More
1
Dogecoin Getting Crushed as Market Fear Spreads
2
ORDI Surges 163.27% Within 24 Hours Despite Recent Market Fluctuations

Crypto prices

More
Bitcoin
Bitcoin
BTC
$106,874.93
+0.00%
Ethereum
Ethereum
ETH
$3,867.7
+1.29%
Tether USDt
Tether USDt
USDT
$1
+0.02%
BNB
BNB
BNB
$1,085.97
+0.23%
XRP
XRP
XRP
$2.34
+1.73%
Solana
Solana
SOL
$184.18
+0.28%
USDC
USDC
USDC
$0.9999
-0.02%
TRON
TRON
TRX
$0.3133
+1.19%
Dogecoin
Dogecoin
DOGE
$0.1868
+0.83%
Cardano
Cardano
ADA
$0.6288
+0.29%
How to sell PI
Bitget lists PI – Buy or sell PI quickly on Bitget!
Trade now
Become a trader now?A welcome pack worth 6200 USDT for new users!
Sign up now
Trade smarter