Also known as: tracked as, CVE-2025-55182, STATIC TUNDRA, also tracked as Sandwo, CovertNetwork-1658, the 7777 Botnet, CVE-2024-39717, Smoke Sandstorm, defense companies, APT33, APT28, Fancy Bear, North Korea, Sandworm Team, UNC1549
UNC5342 is a North Korea-linked APT that employs the EtherHiding technique to deliver malware and facilitate cryptocurrency theft. The actor has been observed deploying EtherRAT and JADESNOW malware, utilizing transaction history as a Dead Drop Resolver to embed payloads directly into the calldata of blockchain transactions. Their operations involve leveraging centralized API services to interact with public blockchains like Ethereum and BNB Smart Chain. The malware is designed to exfiltrate sensitive data, particularly targeting cryptocurrency wallets and credentials.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC5342 is a North Korean APT that exploits blockchain technology to evade detection, distributing malware via the EtherHiding technique and targeting cryptocurrency wallets and financial accounts for monetary theft. The actor combines sophisticated JavaScript loaders (JADESNOW) with persistent backdoors (INVISIBLEFERRET.JAVASCRIPT) and leverages public smart contracts on Ethereum and BNB Smart Chain as resilient C2 infrastructure. Through social engineering campaigns that address crypto developers, UNC5342 harvests credentials, exfiltrates private keys, and orchestrates large‐scale cryptocurrency thefts while remaining hidden behind decentralized transaction data.
Goals & Targeting
The actor seeks to acquire substantial financial gains by targeting entities that manage or transact with large amounts of cryptocurrency. Primary victims are cryptocurrency developers, wallet service providers, and users who hold private keys or use browser extensions for blockchain interactions. Financial gains drive a selective geographic focus on jurisdictions with high crypto activity—US, UK, Canada, Germany, Japan—and in some cases governments or critical infrastructure organizations that may house valuable token‑based assets. UNC5342’s operations reveal an intent to infiltrate systems that store key material and personal data while also leveraging publicly exposed blockchain APIs to stay stealthy. In a broader sense, the APT demonstrates elements of espionage: by embedding code in widely used smart contracts it can potentially monitor and harvest transactional metadata from multiple victims with minimal detection risk.
Enhanced Description
UNC5342 is a state-sponsored threat actor originating from North Korea that has recently attracted attention for its innovative use of blockchain‑based payload delivery. This campaign employs the EtherHiding technique, whereby malicious code is embedded in the calldata field of legitimate transactions on public blockchains such as Ethereum and BNB Smart Chain. The malware chain begins with a lightweight JavaScript downloader—JADESNOW—that retrieves, decodes, and executes a more persistent backdoor named INVISIBLEFERRET.JAVASCRIPT. The attackers exploit the inherent opacity and immutability of smart contracts to evade conventional takedown efforts; transaction logs remain on distributed ledgers while payload data is scrambled with Base‑64 encoding and XOR encryption. The final payload, once in memory, establishes a robust exfiltration channel that can communicate through HTTP(S) or custom protocols over the blockchain itself. UNC5342’s modus operandi extends beyond simple crypto theft: it harvests browser extension secrets, wallets, and MFA tokens, then compiles this data into archived bundles for later exfiltration. The APT demonstrates a clear preference for targeted social‑engineering campaigns directed at developers in the cryptocurrency space, thereby exploiting the high value of digital assets and the relative scarcity of formal security training in that community.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since its first observation in early 2025, UNC5342 has operated with a distinct low‑profile campaign cadence. The actor repeatedly re‑loads malicious payloads from blockchain transactions, making each infection cycle independent of traditional hosting infrastructure. Victims typically fall under the cryptocurrency developer umbrella or are organizations that manage wallet solutions; however, there is evidence of broader attacks on government contractors and financial institutions with blockchain exposure. The campaign follows a two‑stage pattern: an initial JavaScript downloader (often disguised as innocuous website traffic) followed by a persistent backdoor that exfiltrates data through secure HTTPS or custom protocol channels. Each operation ends with encrypted archives of stolen credentials and private keys, ready for monetization via illicit exchanges. Notably, UNC5342 has leveraged the same techniques used in earlier North Korean campaigns (e.g., Quad7 botnet infrastructure to perform credential spraying) and now combines them with blockchain‑based tunneling to increase resilience against takedown efforts.
IOC Patterns
Recommended Actions
Suggested Tags
Sources
Confidence Assessment
The characterization is based on publicly available GTIG analysis and Palo Alto Networks’ Contagious Interview blog, both dated February 2025. While the core tactics around EtherHiding are well documented, details regarding exact dates of first/last activity, full infrastructure topology, and precise geographic victim distribution remain incomplete. Therefore confidence is moderate‑high for the described behaviors but low for quantitative operational metrics such as campaign frequency.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
42
Tools
0
Campaigns
40
IOCs
0
Observed Data
15
Tactics