North Korean Hackers Hide Malware inside Smart Contracts
Crypto-Detective
3
Posts
3
Posters
3
Views
-

Google’s Threat Intelligence Group says North Korean-linked actors have adopted “EtherHiding”, a technique that embeds malicious payloads in smart contracts on public blockchains to steal crypto and data. Attackers first compromise legitimate websites (often via fake job outreach), then use JavaScript loader scripts that trigger the on‑chain payload when victims interact. The method avoids normal takedowns because the malicious code lives in immutable contracts on networks like Ethereum and BNB Chain.