Google Threat Intelligence Group has published research on UNC5342, a North Korean cluster that since February 2025 has been storing malware payloads inside smart contracts on the BNB Smart Chain and Ethereum. GTIG describes it as the first time a nation-state actor has adopted the technique, known as EtherHiding.
The framing everywhere is that this is infrastructure nobody can seize. That is true, and it is not the most useful sentence in the report.
How a contract becomes a dead drop
The malicious payload sits in a smart contract. The implant retrieves it with a read-only call — the kind of query that reads contract state without writing to the chain.
Three things follow from that choice. It creates no transaction, so there is no visible history of the retrieval. It costs no gas, so there is no fee trail. And it leaves nothing for a defender to find on-chain afterwards, because nothing was recorded.
A second mechanism works the same way in reverse. The implant reads the data field of transactions sent to the well-known burn address — the one everyone uses to destroy tokens — and takes its configuration from there. Writing to a burn address looks like nothing in particular on a block explorer.
The economics are the detail worth repeating. GTIG puts the average fee to update the contract at about 1.37 dollars, and counts more than 22 updates in the first four months. Changing the payload, or the command server, or the whole campaign's configuration, costs roughly the price of a coffee and takes one transaction.
The part that is not takedown-proof
Here is the finding the headlines skipped.
The attackers do not run their own blockchain nodes. They reach these contracts through ordinary commercial API services — GTIG names Blockchair, Blockcypher and Ethplorer, and notes the use of a free developer key, with several queried at once as a failsafe.
GTIG's phrasing is precise: UNC5342 is using permissioned services to interact with permissionless blockchains. The chain cannot be taken down. The route to it runs through companies that answer the phone.
GTIG says that when it contacted responsible API providers, they acted quickly — and that several other platforms remained unresponsive. That sentence is the actionable part of this entire report, and it describes a policy problem rather than a technical one.
The lure is a job offer
None of the blockchain machinery matters without the first step, and the first step is a fake recruiter.
UNC5342 runs its delivery through the Contagious Interview campaign: invented companies with websites and social accounts, recruiter profiles on LinkedIn and job boards, and an approach to developers in crypto and technology. Conversations move to Telegram or Discord, where one of two things happens.
Either the candidate is asked to run a coding exercise and downloads a repository that carries the first stage, often pulled through npm. Or the candidate joins a video interview, hits a fabricated error, and is told to install a fix — which is the ClickFix pattern we covered on the Custom GPT campaign, wearing an interview instead of a CAPTCHA.
The chain that follows is a downloader, then an information stealer, then a Python and JavaScript backdoor for persistence. What it takes is specific: browser passwords, session cookies and stored cards from Chrome and Edge, wallet data from MetaMask and Phantom, and password manager contents. It compresses the lot and uploads it to attacker servers and private Telegram chats.
Why a developer is the target
The victim selection is not incidental. A developer in a crypto company is two things at once: a person with a wallet, and a person with credentials to systems that hold other people's wallets.
That is why GTIG describes the campaign as serving both revenue and espionage. It is also why the technique keeps resurfacing: the same smart contract has been tied to a 2025 supply-chain compromise of npm packages, which is what happens when the person you phish publishes code other people install.
GTIG also notes something odd — using two separate blockchains is unusual, and may indicate different North Korean teams working in compartments rather than one operation.
What to do
- Treat an unsolicited recruiter who moves you to Telegram and then sends a coding exercise as hostile by default. Run nothing from it on a machine that holds credentials or a wallet.
- Enforce the rule about pasted commands. A video call that fails and tells you to run something to fix it is the same attack as a CAPTCHA that asks the same, and neither is ever legitimate.
- Watch for workstation traffic to blockchain API services. A developer laptop querying Blockchair or Ethplorer is not normal, is easy to alert on, and is the one network signal this design does not hide.
- If you operate a blockchain API service, this is your problem too. GTIG's report distinguishes the providers that acted from the ones that did not, and that distinction is the only real pressure point in the design.
What is not established
- How many people have been compromised through this campaign, which GTIG does not quantify.
- How much cryptocurrency has been taken through it.
- Whether the compartmentalisation GTIG suspects between blockchains reflects separate teams, which it offers as a possibility rather than a finding.
- Which API providers did not respond, which GTIG does not name.