DPRK-Linked Hackers Add HashHiding to Blockchain C2 Network for Takedown-Resistant Malware
DPRK-linked hackers added Ethereum HashHiding so malware can recover C2 addresses from ordinary transfers.
DPRK-linked operators behind the Cross-Chain TxDataHiding campaign added HashHiding, an Ethereum channel that stores a live C2 IP and port in ordinary transfer recipient addresses. A JavaScript scanner watches signal wallet 0x33ff3edaf55a8e03dcbc7cb40d498a49cd499891 and runs alongside hardcoded and TRON/Aptos-to-BSC recovery paths. Delivery still uses Telegram fake job offers, weaponized GitHub repositories, and trojanized npm packages that deploy the DEV#POPPER Node.js RAT and OmniStealer, which targets browsers, password managers, and 153 crypto wallets. Ransom-ISAC counted 2,655 outbound beacons between June 23 and September 21, 2026.