Threats Tagged 'jadesnow'
View all threats tagged with 'jadesnow'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'jadesnow'
Click on any threat for detailed analysis and mitigation recommendations
North Korean threat actor UNC5342 employs a novel malware delivery technique called 'EtherHiding,' embedding malicious code within smart contracts on public blockchains to create resilient command-and-control infrastructure. The attack chain begins with social engineering, targeting cryptocurrency and technology sector developers via fake recruitment schemes. Loader scripts are injected to fetch payloads from multiple blockchains and API services, complicating detection and mitigation. The malware suite includes JADESNOW, BEAVERTAIL, and INVISIBLEFERRET, which enable data theft and remote control of infected systems. This approach leverages the decentralized and immutable nature of blockchains to evade takedown efforts. The campaign primarily facilitates cryptocurrency theft and espionage. Exploitation does not require prior authentication but relies on user interaction through social engineering. The threat is medium severity but poses significant challenges due to its innovative use of blockchain technology for malware command and control. Join the discussion | AlienVault OTX General | 10/16/2025, 17:53:01 UTC Added: 10/16/2025, 21:28:49 UTC |
Showing 1 to 1 of 1 result