KP

UNC5342UNC5342

Also known as: UNC5342

Origin
KP
Known aliases
1

Profile

UNC5342 is a North Korea-linked APT that employs the EtherHiding technique to deliver malware and facilitate cryptocurrency theft. The actor has been observed deploying EtherRAT and JADESNOW malware, utilizing transaction history as a Dead Drop Resolver to embed payloads directly into the calldata of blockchain transactions. Their operations involve leveraging centralized API services to interact with public blockchains like Ethereum and BNB Smart Chain. The malware is designed to exfiltrate sensitive data, particularly targeting cryptocurrency wallets and credentials.

Aliases· 1

UNC5342

References

  1. https://cloud.google.com/blog/topics/threat-intelligence/dprk-adopts-etherhiding

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
UNC4736
Actor
TA444
Actor
UNC4841
Actor
UNC5337
Actor
APT43
Actor
UNC4393
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.