Malware
JADESNOW
aka ChainedDown
JADESNOW is a JavaScript-based downloader malware family associated with the threat cluster UNC5342.
JADESNOW, also known as ChainedDown, is a JavaScript malware family operated by WageMole.
Background
JADESNOW is a downloader malware family written in JavaScript and tied to the threat cluster UNC5342. It leverages EtherHiding to pull, decrypt, and run malicious payloads stored in smart contracts on the BNB Smart Chain and Ethereum. The data held in those smart contracts may be Base64-encoded and XOR-encrypted. The last payload delivered in a JADESNOW infection chain is typically a more durable backdoor such as INVISIBLEFERRET.JAVASCRIPT.
Source: Malpedia (Fraunhofer FKIE).