DPRK-Linked XCTDH Campaign Adds Ethereum 'HashHiding' to Encode C2 Addresses in Transaction Recipients
North Korea-linked XCTDH operators added HashHiding, an Ethereum channel that encodes a live C2 IP address and port into ordinary transfer recipient addresses, giving their RAT and credential stealer takedown-resistant command infrastructure.
Ransom-ISAC identified HashHiding, a new Ethereum-based command-and-control signaling channel, in September 2026 samples of the DPRK-linked Cross-Chain TxDataHiding (XCTDH) developer-targeting campaign, with on-chain signals beginning in June 2026. The first four bytes of an Ethereum recipient address encode the C2 server's IPv4 address and the next two bytes encode the port; a JavaScript scanner watches signal wallet 0x33ff3edaf55a8e03dcbc7cb40d498a49cd499891, scans public Ethereum blocks, decodes the destination, and fetches code that rebuilds the infection. The channel runs alongside hardcoded recovery paths and existing TRON/Aptos-to-BSC routes, in which XCTDH hides payloads in BNB Smart Chain calldata with TRON and Aptos acting as pointers. Delivery still relies on Telegram fake job offers, weaponized GitHub repositories, and trojanized npm packages, which deploy the DEV#POPPER Node.js RAT (remote control, command execution, keylogging, clipboard monitoring) and OmniStealer, which harvests browser, password manager, cloud, and cryptocurrency wallet data across 153 wallet targets. Ransom-ISAC counted 2,655 signaling transactions between June 23 and September 21, 2026, and the operator changed the encoded C2 destination four times during the observed period.
- Attribution: DPRK/North Korea-linked operators behind the Cross-Chain TxDataHiding (XCTDH) developer-targeting campaign; research attributed to Ransom-ISAC.
- HashHiding is a new Ethereum C2 signaling component identified in September 2026 samples; on-chain signaling began in June 2026.
- Encoding scheme: the first four bytes of the Ethereum recipient address encode the C2 server's IPv4 address and the next two bytes encode the port.
- A JavaScript scanner watches Ethereum signal wallet 0x33ff3edaf55a8e03dcbc7cb40d498a49cd499891, scanning public blocks to decode the destination and fetch code that rebuilds the infection.
- Volume: 2,655 signaling transactions (described as outbound beacons from the signal wallet) between June 23 and September 21, 2026, roughly 90 days; the operator changed the encoded C2 destination four times.
- Delivery lures: Telegram fake job offers, weaponized GitHub repositories, and trojanized npm packages.
- Payloads: the DEV#POPPER Node.js RAT (remote control, command execution, keylogging, clipboard monitoring) and OmniStealer, which targets browsers, password managers, cloud data, and 153 cryptocurrency wallets.
- Resilience: fallback C2 routes via TRON, Aptos, and BNB Smart Chain remain active; XCTDH hides payloads in BSC calldata with TRON and Aptos as pointers, alongside hardcoded recovery paths.
Coverage timelineoldest first · each row is one article
- · 1d agoDPRK-Linked Hackers Add HashHiding to Blockchain C2 Network for Takedown-Resistant Malware
GBHackers· 76
DPRK-linked hackers added Ethereum HashHiding so malware can recover C2 addresses from ordinary transfers.
- · 1d agoHackers Turned Ethereum Into a Secret Messaging System for Malware
Cyber Security News· 68
North Korea-linked XCTDH malware encodes C2 server addresses into Ethereum recipient addresses, giving its RAT and credential stealer resilient command channels.