JADESNOW is a JavaScript-based downloader associated with the DPRK-linked UNC5342 cluster and its Contagious Interview social-engineering operations. It targets software and web developers, particularly personnel in cryptocurrency and technology sectors, through fraudulent recruitment workflows and purported technical assessments. The malware uses the EtherHiding technique to retrieve, decrypt, and execute later-stage payloads held in smart-contract data on Ethereum and BNB Smart Chain. This blockchain-backed delivery design allows operators to change payloads or configuration without replacing the initial downloader and complicates conventional infrastructure takedowns. JADESNOW has been used to deploy JavaScript variants of the INVISIBLEFERRET backdoor, supporting UNC5342 operations directed at cryptocurrency theft and espionage. Observed delivery chains have used malicious code distributed through developer-oriented repositories and package ecosystems, as well as fake job-interview lures, against Windows, macOS, and Linux systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“February 2025 : the North Korean group UNC5342 launches a campaign using the Jadesnow malware.”
CLEARSHORT and JADESNOW both read obfuscated JavaScript or bash stagers from BNB Smart Chain contracts.
It targets developers with fake job offers to deliver the JADESNOW loader and INVISIBLEFERRET backdoor.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
...attacker first gains access to a legitimate website... injects... JavaScript... When a user visits the compromised website, the loader script executes in their browser...
JADESNOW is a JavaScript-based downloader malware family associated with the threat cluster UNC5342. JADESNOW utilizes EtherHiding to fetch, decrypt, and execute malicious payloads from smart contracts on the BNB Smart Chain and Ethereum.
JADESNOW utilizes EtherHiding to fetch, decrypt, and execute malicious payloads from smart contracts on the BNB Smart Chain and Ethereum. The input data stored in the smart contract may be Base64-encoded and XOR-encrypted.
Traditionally, defenders could disrupt attacks by seizing domains or sinkholing IP addresses; however, the integration of blockchain technology renders these methods largely obsolete. By leveraging public ledgers, threat actors have created a resilient C2 layer...
“The contract's call can return, among other things, a URL, a port number, an encryption key, a configuration... Once retrieved by the script, this information is used to send requests to the C2 server.”
dead drop resolver (DDR) is any mechanism where malware fetches its command and control (C2) address at runtime from a third-party, cyberattacker-controlled location instead of hardcoding it. | The loader posts JSON-RPC to the same high-reputation crypto SaaS hosts that wallets and decentralized applications use (Infura, Cloudflare, Binance, publicnode), so host-only network signatures drown in false positives.
These loaders may collect initial system information and download the next stage of malware.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses BNB Smart Chain contracts as a dead drop resolver to retrieve obfuscated JavaScript or bash stagers.
Malware used in a February 2025 campaign attributed in the content to UNC5342.
A loader used in the Contagious Interview campaign to deliver follow-on malware to targeted developers.
A named malware/tool associated with DPRK-linked GitHub repository compromise and blockchain-focused theft campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.