DPRK-Linked Hackers Add HashHiding to Blockchain C2 Network for Takedown-Resistant Malware
DPRK-linked hackers added Ethereum HashHiding so malware can recover C2 addresses from ordinary transfers.
DPRK-linked operators behind the Cross-Chain TxDataHiding campaign added HashHiding, an Ethereum channel that stores a live C2 IP and port in ordinary transfer recipient addresses. A JavaScript scanner watches signal wallet 0x33ff3edaf55a8e03dcbc7cb40d498a49cd499891 and runs alongside hardcoded and TRON/Aptos-to-BSC recovery paths. Delivery still uses Telegram fake job offers, weaponized GitHub repositories, and trojanized npm packages that deploy the DEV#POPPER Node.js RAT and OmniStealer, which targets browsers, password managers, and 153 crypto wallets. Ransom-ISAC counted 2,655 outbound beacons between June 23 and September 21, 2026.
- HashHiding encodes a live IPv4 address and port inside Ethereum recipient addresses.
- XCTDH still hides payloads in BSC calldata, using TRON and Aptos as pointers.
- Lures include Telegram fake jobs, malicious GitHub repos, and trojanized npm packages.
- DEV#POPPER provides remote control, keylogging, and clipboard monitoring; OmniStealer harvests credentials.
- The Ethereum signal wallet sent 2,655 beacons from June 23 to September 21, 2026.
Full article794 words · extracted from gbhackers.com · click to collapse
DPRK-linked operators behind the Cross-Chain TxDataHiding (XCTDH) campaign have expanded their blockchain-backed command-and-control infrastructure with a new Ethereum-based recovery channel dubbed HashHiding.
The technique stores an active C2 IP address and port inside the recipient address of ordinary Ethereum transfers, allowing infected systems to recover attacker infrastructure without relying on domains, smart contracts, or transaction calldata.
The current activity preserves that three-chain architecture while adding Ethereum as a lightweight C2-signaling layer, creating a four-blockchain system designed to withstand conventional disruption efforts.
The newly identified JavaScript component, _Z, was found in a September 2026 /init response delivered by the campaign’s existing BSC payload chain.
After deobfuscation, the approximately 69,470-character module was reduced to code that scans Ethereum mainnet blocks for transactions sent by a hardcoded signal wallet: 0x33ff3edaf55a8e03dcbc7cb40d498a49cd499891.
Rather than putting malicious code in a transaction’s input field, HashHiding encodes just six bytes an IPv4 address and port into the first bytes of the Ethereum to address.
For example, the recipient address 0xB5D6959401bbb5D69594005000ff8C84e0b715b1 decodes to 181[.]214[.]149[.]148:443. The remaining bytes contain a secondary endpoint and padding.
This architecture resembles the recipient-address technique publicly documented as NullReceiver in August 2026.
That research showed DPRK-linked npm malware extracting its C2 location from zero-value Ethereum transfer recipients rather than smart-contract storage or calldata.
Ransom-ISAC’s tracking, however, places the first observed beacon associated with this wider XCTDH campaign on June 23, 2026 weeks before the public NullReceiver disclosure.
HashHiding is not a replacement for Cross-Chain TxDataHiding. The two methods serve different roles.
XCTDH hides large encrypted payloads in BSC transaction calldata, while TRON and Aptos provide indirection by carrying the BSC transaction hashes.
HashHiding carries only a live C2 endpoint, enabling malware to bootstrap or re-bootstrap its communication channel.
The September samples show three C2-resolution paths operating in parallel: a hardcoded endpoint, the TRON/Aptos-to-BSC payload chain, and Ethereum-based HashHiding.

Ransom-ISAC first documented the wider campaign in October 2025, describing how malware used TRON and Aptos as pointer layers to retrieve transaction hashes for encrypted payloads embedded in BSC transaction calldata.
The Ethereum scanner selects public RPC services, retrieves a recent block number, searches backward using exponential offsets, locates a transfer from the signal wallet, decodes the destination address, and fetches /boot from the recovered server.
HashHiding to Blockchain C2
The approach makes address rotation inexpensive. Instead of distributing updated malware or changing a domain, the operator can send another low-value Ethereum transaction to a fabricated recipient address that encodes a replacement IP and port.

The campaign continues to use social engineering against developers, including Telegram-based fake job offers, weaponized GitHub repositories, trojanized npm packages, and malicious configuration files padded with whitespace to conceal appended JavaScript.
Earlier analysis linked the operation to a Node.js RAT called DEV#POPPER.js and the Python-based OmniStealer credential harvester.
The updated /init endpoint returns four components: _U, the C2 base URL; _H, bootstrap code; _B, the DEV#POPPER RAT; and _Z, the HashHiding scanner.
_B launches _Z as a detached background process rather than reserving it as a failover mechanism. This means the Ethereum channel begins operating immediately and independently on every compromised host.
DEV#POPPER now provides WebSocket C2 communications, command execution, shell spawning, clipboard monitoring, keylogging, and IDE-focused persistence.
Separately, the campaign’s dropper chain installs Python and retrieves OmniStealer, which targets browser data, password managers, cloud-storage credentials, and 153 cryptocurrency-wallet targets.

On-chain activity shows 2,655 outbound beacon transactions from the Ethereum signal wallet between June 23 and September 21, 2026.
Observed C2 endpoints include 23[.]27[.]20[.]187 on ports 80 and 443, 181[.]214[.]149[.]147:443, and 181[.]214[.]149[.]148:443.
Defenders should hunt for Node.js processes making unexplained JSON-RPC requests to Ethereum, TRON, Aptos, or BSC providers; investigate JavaScript that calls eth_getTransactionByHash; and monitor outbound traffic from developer environments to the listed IPs.
The persistent BSC infrastructure address 0x9bc1355344b54dedf3e44296916ed15653844509 and the Ethereum signal wallet should also be tracked as high-confidence indicators.
IOCs
| Endpoint | Port | Returns |
|---|---|---|
/init | 443 | 303KB JSON containing _B (the RAT) and _Z (the HashHiding scanner) |
/$/boot | 80 | XOR-encrypted Dropper (installs Python 3.13 and 7-Zip, fetches OmniStealer) |
/$/1 | 80 | XOR-encrypted OmniStealer |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.