Also known as: tracked as
HexagonalRodent is a North Korean threat actor cluster that focuses on large‑scale cryptocurrency theft, primarily targeting developers within the Web3 ecosystem. The group uses AI‑generated LinkedIn lures and fake job interview offers to entice victims into executing malicious code that appears harmless. Technically, HexagonalRodent delivers payloads through a novel blockchain‑based mechanism called EtherHiding, which stores encrypted JavaScript downloaders in public Ethereum or BNB Smart Chain transactions. The JADESNOW downloader is then retrieved from NPM, unpacks further modules, and deploys the Python backdoor INVISIBLEFERRET. This backdoor can execute arbitrary commands, perform lateral movement via account manipulation, and extract sensitive information such as browser credentials (Chrome, Edge) and wallet data for MetaMask, Phantom, and other Web3 wallets. The actor also conducts supply‑chain attacks by compromising legitimate VSX extensions like “fast-draft” to host its malware. Once executed, the malware compresses stolen material into ZIP archives and exfiltrates it through attacker‑controlled servers or private Telegram chats, employing techniques such as masquerading, deobfuscation, and virtualization/sandbox evasion. Overall, HexagonalRodent combines advanced social engineering, blockchain‐based delivery, and classic R2L tactics to achieve its financial objectives while staying obscure and mobile across cloud environments.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
HexagonalRodent, a cluster linked to North Korea’s UNC5342, is a financially motivated actor that steals cryptocurrency by targeting Web3 developers with sophisticated social engineering and blockchain‑based delivery mechanisms. It employs JavaScript downloaders (JADESNOW) and Python backdoors (INVISIBLEFERRET), often hidden in Ethereum or BNB Smart Chain transactions via EtherHiding, to exfiltrate wallet keys and credentials while leveraging supply‑chain attack vectors such as compromised VSX extensions.
Goals & Targeting
HexagonalRodent’s strategic objective is direct monetary gain through the theft of cryptocurrencies. It concentrates on individuals with access to valuable wallets—primarily Web3 developers—as well as finance, defense, government, and IT organizations that might expose high‑value digital assets. The actor’s use of AI‑assisted phishing and blockchain delivery enables rapid, low‑visibility attacks across jurisdictions, fitting a disruptive posture typical of North Korean threat clusters.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
HexagonalRodent has operated in a series of discreet, multi‑stage campaigns from at least 2024 through 2026, targeting developers and technical personnel via social engineering. Victims are chosen for their likely access to high‑value crypto wallets and privileged systems. Attacks typically begin with phishing or supply‑chain lures, deliver a blockchain‑hidden payload, establish persistence through a Python backdoor, and exfiltrate data through covert channels such as Telegram. The actor shows a rapid operational tempo, often reusing the same delivery frameworks while shifting C2 infrastructure via smart contracts.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The evidence strongly supports the attribution of HexagonalRodent to North Korea’s UNC5342, given consistent indicators such as AI‑phishing tactics, blockchain delivery via EtherHiding, and a focus on crypto assets. Confidence is high regarding the financial motive, target profile, and technology stack (JADESNOW, INVISIBLEFERRET). However, gaps remain in precise campaign timelines, detailed internal procedures, and the full scope of victim impact beyond publicly reported incidents.
No campaigns linked yet.
No observed data linked yet.
22
Techniques
51
Tools
0
Campaigns
5
IOCs
0
Observed Data
9
Tactics