Unc5342 — Threat Actor Profile, Campaigns & Targets

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
May 26, 2026
Last Seen
August 8, 2026

Related Threat Clusters

  • North Korean Hackers Utilize EtherHiding for Cryptocurrency Theft

    The Google Threat Intelligence Group (GTIG) reports that North Korean threat actor UNC5342 has adopted a new technique called EtherHiding to deliver malware and facilitate cryptocurrency theft. This method embeds…

    3 articles · Updated May 26, 2026
  • Cybercriminals Exploit BNB Chain for Malware via Fake CAPTCHAs

    Microsoft Threat Intelligence has reported a new malware campaign utilizing the BNB Smart Chain, employing a technique called EtherHiding. This method allows hackers to store malicious code within blockchain smart…

    12 articles · Updated August 7, 2026
  • ClearFake Campaign Uses Smart Contracts for C&C on BSC Testnet

    In May 2026, TrendAI™ Research reported on a cyber intrusion involving the ClearFake campaign, where threat actors utilized the EtherHiding technique to deliver payloads via smart contracts on the BNB Smart Chain…

    2 articles · Updated May 26, 2026

Recent Intelligence Reports

  • EtherHiding — metamask.io · August 8, 2026
  • EtherHiding — www.bleepingcomputer.com · May 26, 2026
  • Dprk Adopts Etherhiding — cloud.google.com · May 26, 2026
  • Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet — Trendmicro · May 26, 2026
  • Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet — Feeds.Trendmicro · May 26, 2026

CVSS v3.1 Breakdown