Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors HexagonalRodent

Also known as: tracked as

Description

HexagonalRodent is a North Korean threat actor cluster that focuses on large‑scale cryptocurrency theft, primarily targeting developers within the Web3 ecosystem. The group uses AI‑generated LinkedIn lures and fake job interview offers to entice victims into executing malicious code that appears harmless. Technically, HexagonalRodent delivers payloads through a novel blockchain‑based mechanism called EtherHiding, which stores encrypted JavaScript downloaders in public Ethereum or BNB Smart Chain transactions. The JADESNOW downloader is then retrieved from NPM, unpacks further modules, and deploys the Python backdoor INVISIBLEFERRET. This backdoor can execute arbitrary commands, perform lateral movement via account manipulation, and extract sensitive information such as browser credentials (Chrome, Edge) and wallet data for MetaMask, Phantom, and other Web3 wallets. The actor also conducts supply‑chain attacks by compromising legitimate VSX extensions like “fast-draft” to host its malware. Once executed, the malware compresses stolen material into ZIP archives and exfiltrates it through attacker‑controlled servers or private Telegram chats, employing techniques such as masquerading, deobfuscation, and virtualization/sandbox evasion. Overall, HexagonalRodent combines advanced social engineering, blockchain‐based delivery, and classic R2L tactics to achieve its financial objectives while staying obscure and mobile across cloud environments.

Goals & Targeting

Targeted Sectors

Financial services
Defense
Government
Information technology

Targeted Countries / Regions

KP

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

HexagonalRodent, a cluster linked to North Korea’s UNC5342, is a financially motivated actor that steals cryptocurrency by targeting Web3 developers with sophisticated social engineering and blockchain‑based delivery mechanisms. It employs JavaScript downloaders (JADESNOW) and Python backdoors (INVISIBLEFERRET), often hidden in Ethereum or BNB Smart Chain transactions via EtherHiding, to exfiltrate wallet keys and credentials while leveraging supply‑chain attack vectors such as compromised VSX extensions.

Goals & Targeting

HexagonalRodent’s strategic objective is direct monetary gain through the theft of cryptocurrencies. It concentrates on individuals with access to valuable wallets—primarily Web3 developers—as well as finance, defense, government, and IT organizations that might expose high‑value digital assets. The actor’s use of AI‑assisted phishing and blockchain delivery enables rapid, low‑visibility attacks across jurisdictions, fitting a disruptive posture typical of North Korean threat clusters.

Enhanced Description

Key Capabilities

  • Deploy JavaScript downloader via NPM (JADESNOW) to fetch encrypted payloads from blockchain transactions
  • Store malicious code on Ethereum/BNB Smart Chain using EtherHiding and dynamically shift between chains
  • Install portable Python backdoor (INVISIBLEFERRET) for command execution, lateral movement, and persistence
  • Steal browser credentials and cryptocurrency wallet keys (MetaMask, Phantom, Chrome, Edge)
  • Conduct AI‑driven LinkedIn phishing campaigns with fake job interview offers
  • Execute supply‑chain attacks through compromised VSX or Fast‑Draft extensions
  • Split payload across multiple blockchain transaction data entries
  • Exfiltrate collected data compressed into ZIP archives via attacker servers or Telegram chats

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Command and Control
Exfiltration
Defense Evasion
Discovery
Privilege Escalation
Lateral Movement

ATT&CK Techniques

T1047
T1564.008
T1530
T1082
T1140
T1219
T1036
T1055
T1059
T1059.001
T1083
T1114.003
T1497
T1098
T1027
T1486
T1204.004
T1018
T1105
T1078.004
T1566
T1041

Software / Tooling

JADESNOW
EtherHiding
INVISIBLEFERRET
BeaverTail
OtterCookie
Portable Python interpreter
fast-draft VSX extension

Campaigns & Victims

HexagonalRodent has operated in a series of discreet, multi‑stage campaigns from at least 2024 through 2026, targeting developers and technical personnel via social engineering. Victims are chosen for their likely access to high‑value crypto wallets and privileged systems. Attacks typically begin with phishing or supply‑chain lures, deliver a blockchain‑hidden payload, establish persistence through a Python backdoor, and exfiltrate data through covert channels such as Telegram. The actor shows a rapid operational tempo, often reusing the same delivery frameworks while shifting C2 infrastructure via smart contracts.

IOC Patterns

  • Malicious blockchain addresses used for command & control
  • Suspicious LinkedIn URLs delivering phishing or malicious payloads
  • Ethereum/BNB smart contract transaction address patterns
  • Base64‑encoded XOR‑encrypted payload data
  • ZIP archive exfiltration to remote server or Telegram chat
  • Domain indicators (e.g., cisa.gov, Mallory.ai)
  • Email address indicators
  • SHA-256 hash identifiers

Recommended Actions

  • Monitor outbound traffic to public blockchain networks (Ethereum, BNB Smart Chain) and block known malicious contract addresses
  • Deploy threat intelligence feeds that correlate IPs, domains, and blockchain indicators linked to HexagonalRodent
  • Enhance user training against LinkedIn‑based phishing and verify authenticity of recruitment messages
  • Implement sandboxing and behavior monitoring for newly delivered JavaScript payloads to detect crypto‑mining or credential‑stealing capabilities
  • Develop YARA rules (e.g., AntiDebug_antiVM) to detect virtualization/sandbox evasion techniques such as T1497
  • Add monitoring for file‑discovery commands coupled with recent external downloads, triggering alerts
  • Detect and alert on masquerading of legitimate binaries used maliciously (e.g., SolarWinds or mshta files)

Suggested Tags

North_Korea
DPRK
UNC5342
HexagonalRodent
Crypto_theft
Blockchain_based_delivery
AI_assisted_phishing
EtherHiding
Job_Interview_Phishing
Smart_Contract_Malware
Python_Backdoor
Credential_Harvesting
Browser_Credential_Theft
Telegram_Exfiltration
Remote_Access_Tools
Account_Manipulation

Confidence Assessment

The evidence strongly supports the attribution of HexagonalRodent to North Korea’s UNC5342, given consistent indicators such as AI‑phishing tactics, blockchain delivery via EtherHiding, and a focus on crypto assets. Confidence is high regarding the financial motive, target profile, and technology stack (JADESNOW, INVISIBLEFERRET). However, gaps remain in precise campaign timelines, detailed internal procedures, and the full scope of victim impact beyond publicly reported incidents.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.recordedfuture.com — Cited by web research for: T1083
  2. redcanary.com — Cited by web research for: T1027
  3. cloud.google.com — Cited by web research for: Payload
  4. attack.mitre.org — Cited by web research for: Interception
  5. malpedia.caad.fkie.fraunhofer.de — Cited by web research for: curl
  6. https://lazarus.day/reports/hexagonalrodent-dprk-ai-powered-crypto-theft-campaign-using-linkedin-lures- — Cited by AI analysis.
  7. https://falconfeeds.io/blogs/hexagonalrodent-dprk-ai-crypto-theft-linkedin-malware-web3-targeting — Cited by AI analysis.

Intel Summary

22

Techniques

51

Tools

0

Campaigns

5

IOCs

0

Observed Data

9

Tactics

Tags

Critical Infrastructure
Supply Chain Attack
Backdoor / C2
APT
crypto-theft
Web3
supply-chain
phishing
developer-tools
North_Korea
DPRK
UNC5342
HexagonalRodent
Crypto_theft
Blockchain_based_delivery
AI_assisted_phishing
EtherHiding
Job_Interview_Phishing
Smart_Contract_Malware
Python_Backdoor
Credential_Harvesting
Browser_Credential_Theft
Telegram_Exfiltration
Remote_Access_Tools
Account_Manipulation

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
North Korea (KP)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.