Hackers Turned Ethereum Into a Secret Messaging System for Malware
North Korea-linked XCTDH malware encodes C2 server addresses into Ethereum recipient addresses, giving its RAT and credential stealer resilient command channels.
Ransom-ISAC identified a new Ethereum C2 signaling component, dubbed HashHiding, in September 2026 samples of the North Korea-linked XCTDH developer-targeting campaign; on-chain signals began in June 2026 with 2,655 transactions over 90 days. The first four bytes of the recipient address encode the C2 server IP and the next two the port, letting the malware scan public Ethereum blocks, decode the destination, and fetch code that rebuilds the infection. Delivered via fake job offers, tainted repositories, and malicious packages, it installs a cross-platform RAT (command execution, keylogging, clipboard monitoring) plus a stealer targeting browser, password manager, cloud, and cryptocurrency wallet data across 153 wallet targets. Fallback C2 routes via TRON, Aptos, and BNB Smart Chain remain active, and the operator changed encoded destinations four times during the observed period.
- Ethereum recipient addresses encode C2 IP and port, decoded from public block queries
- 2,655 signaling transactions over 90 days; operator changed C2 destination four times
- Fake job offers and poisoned packages install RAT plus credential stealer
- Stealer targets browser, password manager, cloud, and 153 cryptocurrency wallet sources
- Fallback C2 paths via TRON, Aptos, and BNB Smart Chain remain active
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | blastapi.io | ic Ethereum service named in the detection rule. RPC domain blastapi.io Legitimate public Ethereum service named in the detection r |
| domain | bsc-dataseed.binance.org | ic Ethereum service named in the detection rule. RPC domain bsc-dataseed.binance.org Legitimate BSC service queried by the loader. Note: IP addr |
| domain | eth.drpc.org | ic Ethereum service named in the detection rule. RPC domain eth.drpc.org Legitimate public Ethereum service named in the detection r |
| domain | ethereum-rpc.publicnode.com | Script returned during Ethereum-based recovery. RPC domain ethereum-rpc.publicnode.com Legitimate public Ethereum service named in the detection r |
| md5 | 33ff3edaf55a8e03dcbc7cb40d498a49 | r of the observed beacon transactions. Wallet match pattern 33ff3edaf55a8e03dcbc7cb40d498a49 Partial sender address used by the scanner and detection ru |
Full article1,147 words · extracted from cybersecuritynews.com · click to collapse
A North Korea-linked malware campaign has found a way to keep infected computers connected to its operators. Instead of storing malware on Ethereum, the attackers hide the location of a control server inside cryptocurrency transfers.
The campaign reaches developers through fake job offers, tainted code repositories and malicious software packages. Running the code can install a remote access tool and a credential stealer across Windows, macOS and Linux.
Researchers from Ransom-ISAC identified the new Ethereum component in September 2026 samples of XCTDH.
Ransom-ISAC said in a report shared with Cyber Security News (CSN) that the technique gives the malware another way to find its operator if other routes are disrupted.
The operation was first documented in October 2025, but the researchers found its Ethereum signals began in June 2026. They counted 2,655 transactions over 90 days. The report does not establish how many computers were infected or how much data was stolen.
Hackers Turned Ethereum Into a Secret Messaging System
The method, called HashHiding by Ransom-ISAC, turns the recipient address of an Ethereum transfer into a tiny message. Its first four bytes represent the server’s internet address, and the next two represent its port.
The remaining bytes contain a second endpoint and padding. That is different from placing full malware payloads in blockchain transaction data.
These transfers carry no smart contract call or hidden script. Most move no cryptocurrency, while a few transfer a tiny amount to an address whose private key nobody is expected to control.
The malware watches transactions sent from the operator’s signaling wallet. It scans recent Ethereum blocks through public access points, finds a matching transfer, decodes its recipient address and contacts the server it reveals.
The server then supplies code that can rebuild the infection. Earlier reporting on malware servers hidden inside Ethereum transfers described a related method called NullReceiver.
.webp)
Ransom-ISAC credits that earlier public description, while tracing this separate campaign through its own on-chain collection. The distinction matters because a blockchain address here acts as a signpost, not a storage site for malware.
The operator changed the encoded destination four separate times during the observed period. The first two signals pointed to the same internet address on different ports; later signals moved to another address range. One subsequent change altered only the final number of the server address, a shift that could escape blocklists.
Multiple Paths Keep Malware Connected
Ethereum is only one part of this operation. The initial loader checks transactions on TRON, with Aptos as a backup, to locate encrypted JavaScript stored in BNB Smart Chain transactions. That older route delivers code, while the Ethereum route supplies a fresh server location.
The attack begins when a developer follows a fake recruitment prompt and runs a poisoned project or package. As JavaScript loaders hidden in repositories have shown, a project can carry code that contacts blockchain services after execution.
Here, the hidden loader brings in later stages without an obvious malicious download link. The updated remote access tool can run commands, record keystrokes and watch the clipboard.
A separate one-time stealer seeks browser information, password manager data, cloud storage credentials and cryptocurrency wallet material. Researchers counted 153 wallet targets and said stolen data leaves through a messaging bot interface.
The Ethereum scanner starts alongside the remote access tool, not only after a connection fails. A hardcoded server location and the older cross-chain path also remain active. This parallel design means blocking one server or one blockchain access point may leave another route open.
The broader risk resembles developer attacks using blockchain payloads, where a trusted-looking development task becomes the first step of compromise.
Ransom-ISAC recommends watching for unexpected Ethereum block queries followed by unusual server connections and monitoring the signaling wallet for new destination changes.
Teams investigating a suspected infection should also examine Node.js processes running evaluated code and review developer environments.
Removing a known server alone is not enough if the malware can read a newer server address from public blockchain records and start the chain again.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| C2 address | 23[.]27[.]20[.]143:27017 | Server and port listed for the October 2025 campaign. |
| C2 endpoint | 23[.]27[.]20[.]187:80 | First observed Ethereum-encoded destination. |
| C2 endpoint | 23[.]27[.]20[.]187:443 | Second observed Ethereum-encoded destination. |
| C2 endpoint | 181[.]214[.]149[.]147:443 | Third observed Ethereum-encoded destination. |
| C2 endpoint | 181[.]214[.]149[.]148:443 | Fourth observed Ethereum-encoded destination; the report also describes a port 80 dropper path on this IP. |
| Encoded Ethereum recipient | 0x171B14bB0050171b14Bb01BB398EAAB6441Fbd47 | First observed destination, encoding the port 80 C2 endpoint. |
| Encoded Ethereum recipient | 0x171B14bb01bB171B14BB0050EB7f39C35C47E682 | Second observed destination, encoding the port 443 C2 endpoint. |
| Encoded Ethereum recipient | 0xB5D6959301bbB5D69593005000FfABa8a5A2ADA2 | Third observed destination. |
| Encoded Ethereum recipient | 0xB5D6959401bbb5D69594005000ff8C84e0b715b1 | Fourth observed destination. |
| Ethereum signaling wallet | 0x33ff3edaf55a8e03dcbc7cb40d498a49cd499891 | Sender of the observed beacon transactions. |
| Wallet match pattern | 33ff3edaf55a8e03dcbc7cb40d498a49 | Partial sender address used by the scanner and detection rule. |
| BSC sender | 0x9bc1355344b54dedf3e44296916ed15653844509 | Address reported as shared with the October 2025 campaign. |
| BSC transaction hash | 0x84e8cecd5b077eef530e7d69d546e2555199cb61759d1224d31cb31750788f62 | Chain 1 payload leading to the RAT and Ethereum scanner. |
| BSC transaction hash | 0x610c9ec972545b8df6e3aaecc7a8ab5f2f2445cf0bfbd6ee026e618d07b29e22 | Chain 2 payload leading to the dropper. |
| TRON wallet | TCqf6ZkaQD84vYsC2cuu1jRwB6JveTaRrF | Chain 1 transaction pointer. |
| TRON wallet | TFMryB9m6d4kBMRjEVyFRbqKSV1cV2NcpH | Chain 2 transaction pointer. |
| TRON wallet | TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7mAP | Example wallet cited for the earlier XCTDH flow. |
| Aptos fallback | 0x9d202c824402ca89e9aaccd2390b6f8b332ae743caa1469c695feb2781d56519 | Chain 1 fallback identifier. |
| Aptos fallback | 0x3d2075f97b7b1e3234bd653779d21c605d7d8c6ec9c98d983880be5c7f4f9471 | Chain 2 fallback identifier. |
| XOR key | 2\[gWfGj;<:-93Z^C | Chain 1 BSC payload decryption key, shown exactly as extracted from the report. |
| XOR key | m6:tTh^D)cBz?NM] | Chain 2 BSC payload decryption key. |
| XOR key | ThZG+0jfXE6VAGOJ | Dropper-response decryption key. |
| C2 path | /init | Port 443 endpoint returning the RAT and scanner. |
| C2 path | /$/boot | Port 80 endpoint returning the encrypted dropper. |
| C2 path | /$/1 | Port 80 endpoint returning OmniStealer. |
| C2 path | /boot | Port 443 Ethereum recovery endpoint. |
| Campaign marker | global.i = '5-3-132' | Marker in the initial code. |
| Version marker | /*RS260605*/ | Ethereum scanner marker. |
| Build marker | B9=260924 | OmniStealer build marker. |
| User-Agent | Python-urllib/3.13 | User-Agent spoofed by the Node.js loader. |
| HTTP header | Sec-V | Custom header on the dropper request. |
| File name | config.js | Example poisoned repository file in the September chain. |
| File name | tailwind.config.js | Example weaponized file in the earlier chain. |
| File name | boot.js | Script returned during Ethereum-based recovery. |
| RPC domain | ethereum-rpc.publicnode.com | Legitimate public Ethereum service named in the detection rule. |
| RPC domain | eth.drpc.org | Legitimate public Ethereum service named in the detection rule. |
| RPC domain | blastapi.io | Legitimate public Ethereum service named in the detection rule. |
| RPC domain | bsc-dataseed.binance.org | Legitimate BSC service queried by the loader. |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.