Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC5342

Also known as: tracked as, CVE-2025-55182, STATIC TUNDRA, also tracked as Sandwo, CovertNetwork-1658, the 7777 Botnet, CVE-2024-39717, Smoke Sandstorm, defense companies, APT33, APT28, Fancy Bear, North Korea, Sandworm Team, UNC1549

Description

UNC5342 is a North Korea-linked APT that employs the EtherHiding technique to deliver malware and facilitate cryptocurrency theft. The actor has been observed deploying EtherRAT and JADESNOW malware, utilizing transaction history as a Dead Drop Resolver to embed payloads directly into the calldata of blockchain transactions. Their operations involve leveraging centralized API services to interact with public blockchains like Ethereum and BNB Smart Chain. The malware is designed to exfiltrate sensitive data, particularly targeting cryptocurrency wallets and credentials.

Goals & Targeting

Targeted Sectors

Financial services
Government
Energy
Defense
Healthcare
Manufacturing
Maritime
Telecommunications
Information technology
Critical infrastructure
Aerospace
Transportation
Media
Aviation
Education
Chemical
Think tank
Construction
Oil gas
Hospitality
Non profit
Nuclear
Legal services

Targeted Countries / Regions

KP
CN
US
UA
IN
JP
AU
CA
IR
KR
GB
PL
SG
VN
TW
RU
DE
KZ
IL
TR
FR
BR
MX
ES
IT

AI Analysis

Grounded in web research
· 3 hours ago

Executive Summary

UNC5342 is a North Korean APT that exploits blockchain technology to evade detection, distributing malware via the EtherHiding technique and targeting cryptocurrency wallets and financial accounts for monetary theft. The actor combines sophisticated JavaScript loaders (JADESNOW) with persistent backdoors (INVISIBLEFERRET.JAVASCRIPT) and leverages public smart contracts on Ethereum and BNB Smart Chain as resilient C2 infrastructure. Through social engineering campaigns that address crypto developers, UNC5342 harvests credentials, exfiltrates private keys, and orchestrates large‐scale cryptocurrency thefts while remaining hidden behind decentralized transaction data.

Goals & Targeting

The actor seeks to acquire substantial financial gains by targeting entities that manage or transact with large amounts of cryptocurrency. Primary victims are cryptocurrency developers, wallet service providers, and users who hold private keys or use browser extensions for blockchain interactions. Financial gains drive a selective geographic focus on jurisdictions with high crypto activity—US, UK, Canada, Germany, Japan—and in some cases governments or critical infrastructure organizations that may house valuable token‑based assets. UNC5342’s operations reveal an intent to infiltrate systems that store key material and personal data while also leveraging publicly exposed blockchain APIs to stay stealthy. In a broader sense, the APT demonstrates elements of espionage: by embedding code in widely used smart contracts it can potentially monitor and harvest transactional metadata from multiple victims with minimal detection risk.

Enhanced Description

UNC5342 is a state-sponsored threat actor originating from North Korea that has recently attracted attention for its innovative use of blockchain‑based payload delivery. This campaign employs the EtherHiding technique, whereby malicious code is embedded in the calldata field of legitimate transactions on public blockchains such as Ethereum and BNB Smart Chain. The malware chain begins with a lightweight JavaScript downloader—JADESNOW—that retrieves, decodes, and executes a more persistent backdoor named INVISIBLEFERRET.JAVASCRIPT. The attackers exploit the inherent opacity and immutability of smart contracts to evade conventional takedown efforts; transaction logs remain on distributed ledgers while payload data is scrambled with Base‑64 encoding and XOR encryption. The final payload, once in memory, establishes a robust exfiltration channel that can communicate through HTTP(S) or custom protocols over the blockchain itself. UNC5342’s modus operandi extends beyond simple crypto theft: it harvests browser extension secrets, wallets, and MFA tokens, then compiles this data into archived bundles for later exfiltration. The APT demonstrates a clear preference for targeted social‑engineering campaigns directed at developers in the cryptocurrency space, thereby exploiting the high value of digital assets and the relative scarcity of formal security training in that community.

Key Capabilities

  • Evasion via blockchain‑based payload storage (EtherHiding)
  • JavaScript‑based downloader (JADESNOW) for credential harvesting
  • Persistent backdoor execution (INVISIBLEFERRET.JAVASCRIPT)
  • Smart contract exploitation for C2 and data exfiltration
  • Social engineering targeting cryptocurrency community
  • Credential theft from browser extensions and wallet software
  • Multi‑stage archive and staging of stolen data

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Credential Access
Discovery
Command and Control
Exfiltration
Impact

ATT&CK Techniques

T1583.001 Acquire Infrastructure: Deploying malicious smart contracts on public blockchains T1059.003 Windows Command Shell T1059.001 PowerShell T1074 Data Staged T1560 Archive Collected Data T1041 Exfiltration Over C2 Channel T1105 Ingress Tool Transfer T1203 Exploitation for Client Execution T1140 Deobfuscate/Decode Files or Information T1111 Multi‑Factor Authentication Interception
T1584 Compromise Infrastructure: Control over blockchain nodes and smart contract manipulation

Software / Tooling

JADESNOW
INVISIBLEFERRET.JAVASCRIPT
EtherRAT (legacy)
PowerShell scripts
Mshta
BITS Job launcher

Campaigns & Victims

Since its first observation in early 2025, UNC5342 has operated with a distinct low‑profile campaign cadence. The actor repeatedly re‑loads malicious payloads from blockchain transactions, making each infection cycle independent of traditional hosting infrastructure. Victims typically fall under the cryptocurrency developer umbrella or are organizations that manage wallet solutions; however, there is evidence of broader attacks on government contractors and financial institutions with blockchain exposure. The campaign follows a two‑stage pattern: an initial JavaScript downloader (often disguised as innocuous website traffic) followed by a persistent backdoor that exfiltrates data through secure HTTPS or custom protocol channels. Each operation ends with encrypted archives of stolen credentials and private keys, ready for monetization via illicit exchanges. Notably, UNC5342 has leveraged the same techniques used in earlier North Korean campaigns (e.g., Quad7 botnet infrastructure to perform credential spraying) and now combines them with blockchain‑based tunneling to increase resilience against takedown efforts.

IOC Patterns

  • Spear‑phishing emails targeting crypto community members
  • JavaScript downloader URLs served via public DNS or CDN domains
  • EtherHiding payload retrieval from transaction calldata on Ethereum/BNB Smart Chain
  • C2 traffic over HTTPS or custom protocols embedded in blockchain logs
  • Use of smart contracts to store encrypted binaries
  • Malicious scripts delivered through legitimate cryptocurrency wallets/extensions

Recommended Actions

  • Deploy advanced endpoint detection that flags unexpected JavaScript execution and PowerShell activity originating from non‑trusted URLs.
  • Implement network segmentation and strict egress controls for devices interacting with public cryptocurrency nodes and wallets.
  • Enforce MFA across all accounts, especially those used for managing private keys or wallet software. Use Web Application Firewalls to spot and block attempts to fetch data from unauthorized smart contracts. Educate developers and staff in the crypto space on phishing awareness and secure coding practices. Deploy sensors that monitor outgoing traffic to known blockchain nodes for anomalous data patterns.
  • Leverage threat hunting queries that detect Base64/XOR‑encoded payloads being executed
  • Maintain currency of domain blocklists for known malicious botnet infrastructure (e.g. Quad7, 7777 Botnet).

Suggested Tags

APT
North Korean Threat Actor
Cryptocurrency Theft
Blockchain Delivery
State-sponsored
Financial Cybercrime
Ethereum
BNB Smart Chain

Confidence Assessment

The characterization is based on publicly available GTIG analysis and Palo Alto Networks’ Contagious Interview blog, both dated February 2025. While the core tactics around EtherHiding are well documented, details regarding exact dates of first/last activity, full infrastructure topology, and precise geographic victim distribution remain incomplete. Therefore confidence is moderate‑high for the described behaviors but low for quantitative operational metrics such as campaign frequency.

ATT&CK Techniques

Defense impairment
1 technique
Lateral Movement
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 11 Filename 2 SHA-256 Hash 4 URL 2 IPv4 Address 1

References

  1. attack.mitre.org — Cited by web research for: STATIC TUNDRA
  2. www.paloaltonetworks.com — Cited by web research for: Smoke Sandstorm
  3. cloud.google.com — Cited by web research for: T1218.005
  4. www.group-ib.com — Cited by web research for: T1059.001
  5. attack.mitre.org — Cited by web research for: T1595
  6. cloud.google.com — Cited by web research for: InvisibleFerret
  7. unit42.paloaltonetworks.com — Cited by web research for: Vidar

Intel Summary

40

Techniques

42

Tools

0

Campaigns

40

IOCs

0

Observed Data

15

Tactics

Tags

APT
Financial Targeting
Backdoor / C2
Data Exfiltration

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
K
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.