Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
New Botnet Burns AI Credits, Steals Data
September 29, 2026
New 7-Zip Installer Malware Evades Detection
September 29, 2026
Attackers Exploit Ethereum Blockchain for Covert Malware Communications
September 29, 2026
Home/Threats/Attackers Exploit Ethereum Blockchain for Covert Malware Communications
Threats

Attackers Exploit Ethereum Blockchain for Covert Malware Communications

Key Takeaways A North Korea-linked threat actor is leveraging the Ethereum blockchain to conceal command-and-control (C2) server locations for its malware. The attackers embed C2 server IP addresses...

Emy Elsamnoudy
Emy Elsamnoudy
September 29, 2026 6 Min Read
3 0

Key Takeaways

  • A North Korea-linked threat actor is leveraging the Ethereum blockchain to conceal command-and-control (C2) server locations for its malware.
  • The attackers embed C2 server IP addresses and ports within the recipient addresses of seemingly innocuous Ethereum transactions, a technique dubbed “HashHiding.”
  • This multi-platform malware campaign targets developers through fake job offers and malicious code, installing remote access tools and credential stealers on Windows, macOS, and Linux systems.
  • The use of multiple blockchain networks (Ethereum, TRON, Aptos, BNB Smart Chain) and redundant C2 communication channels enhances the malware’s resilience against detection and disruption.
  • Organizations should monitor for unusual Ethereum blockchain queries and unexpected server connections, particularly from developer environments, to detect and mitigate this sophisticated threat.

Hackers Turn Ethereum into Covert Malware Communication Channel

A sophisticated malware campaign, attributed to a North Korea-linked threat group, has adopted an innovative method for maintaining communication with infected systems. Instead of storing malware directly on the Ethereum blockchain, the attackers are cleverly embedding the location of their command-and-control (C2) servers within cryptocurrency transaction data. This novel approach allows the malware to retrieve updated C2 server details discreetly.

Table Of Content

  • Key Takeaways
  • Hackers Turn Ethereum into Covert Malware Communication Channel
  • HashHiding: The Ethereum Obfuscation Technique
  • Multiple Paths Ensure Malware Persistence
  • What You Should Do

The campaign primarily targets developers, luring them with deceptive job opportunities, compromised code repositories, and malicious software packages. Execution of the tainted code leads to the installation of a potent remote access tool (RAT) and a credential stealer, capable of operating across Windows, macOS, and Linux platforms.

HashHiding: The Ethereum Obfuscation Technique

Researchers at Ransom-ISAC identified this new Ethereum-based component in September 2026 samples of the XCTDH malware. Ransom-ISAC, in a report shared with Cyber Security News (CSN), highlighted that this technique provides the malware with a robust alternative C2 channel, ensuring continued operation even if primary communication routes are compromised.

The method, which Ransom-ISAC has named “HashHiding,” ingeniously transforms the recipient address of an Ethereum transaction into a minute message. The initial four bytes of this address encode the server’s internet address, while the subsequent two bytes specify the corresponding port. Any remaining bytes within the address may contain a secondary endpoint or serve as padding. This differs significantly from previous tactics that involved embedding entire malware payloads within blockchain transaction data.

Crucially, these transactions typically involve no smart contract calls or embedded scripts. Most HashHiding transfers move zero cryptocurrency, while a few send a negligible amount to an address for which no one is expected to hold the private key. This makes the transactions appear as ordinary, low-value blockchain activity, further aiding in their stealth.

The infected malware continuously monitors transactions originating from the operator’s designated signaling wallet. It achieves this by scanning recent Ethereum blocks via public access points. Upon identifying a matching transaction, the malware decodes the recipient address to extract the hidden C2 server information and subsequently establishes contact with that server. The C2 server then delivers additional code, facilitating the re-establishment or continuation of the infection. While earlier reports described a related technique called NullReceiver for hiding malware servers in Ethereum transfers, Ransom-ISAC distinguishes this campaign due to its unique use of a blockchain address as a dynamic signpost rather than a static storage location for malicious code.

During the observed period, the threat actor altered the encoded destination four times. The first two changes directed to the same internet address but utilized different ports. Subsequent changes shifted the C2 to an entirely new address range. One notable change involved only modifying the final octet of the server’s IP address, a subtle alteration designed to evade common blocklist detections.

Multiple Paths Ensure Malware Persistence

The Ethereum component is just one facet of a multi-layered C2 infrastructure. The initial malware loader also inspects transactions on the TRON blockchain, with Aptos serving as a backup, to locate encrypted JavaScript payloads stored within BNB Smart Chain transactions. This established, older pathway delivers the core malicious code, while the newly discovered Ethereum route primarily provides dynamic updates for the C2 server location.

The attack chain commences when a developer interacts with a fraudulent recruitment advertisement and executes a compromised project or software package. As demonstrated by JavaScript loaders concealed in various repositories, such projects can harbor code that initiates communication with blockchain services upon execution. In this particular campaign, the hidden loader retrieves subsequent malware stages without relying on easily identifiable malicious download links. The updated remote access tool boasts capabilities such as command execution, keystroke logging, and clipboard monitoring.

A separate, one-time information stealer module targets a wide array of sensitive data, including browser information, password manager databases, cloud storage credentials, and cryptocurrency wallet material. Researchers documented 153 distinct cryptocurrency wallet targets, noting that stolen data is exfiltrated via a messaging bot interface.

The Ethereum scanner operates concurrently with the remote access tool, rather than activating only as a fallback mechanism. A hardcoded C2 server location and the pre-existing cross-chain communication path also remain active. This redundant design ensures that blocking a single server or a specific blockchain access point may not be sufficient to neutralize the threat, as alternative routes remain operational.

The overarching risk mirrors other developer-focused attacks that leverage blockchain for payload delivery, where a seemingly legitimate development task becomes the initial vector for compromise.

What You Should Do

  • Monitor Blockchain Activity: Implement monitoring for unexpected queries to Ethereum public RPC (Remote Procedure Call) services (e.g., ethereum-rpc.publicnode.com, eth.drpc.org, blastapi.io) originating from internal networks, especially developer workstations.
  • Inspect Outbound Connections: Scrutinize outbound network connections for unusual server communications following any blockchain queries. Look for connections to the identified C2 endpoints (e.g., 23.27.20.143:27017, 181.214.149.147:443, 181.214.149.148:443).
  • Review Developer Environments: Conduct thorough reviews of developer environments for any signs of compromise, including unexpected Node.js processes executing evaluated code.
  • Implement Strong Software Supply Chain Security: Exercise extreme caution with third-party code, open-source projects, and software packages. Verify the authenticity and integrity of all development tools and libraries.
  • Monitor Signaling Wallets: Keep a close watch on the identified Ethereum signaling wallet (0x33ff3edaf55a8e03dcbc7cb40d498a49cd499891) for new transaction patterns that could indicate changes in C2 destinations.
  • Educate Developers: Provide continuous training to developers on social engineering tactics, particularly those involving fake job offers and poisoned code repositories.
  • Utilize IoCs for Detection: Integrate the provided Indicators of Compromise (IoCs) into your threat intelligence platforms (e.g., MISP, VirusTotal) and Security Information and Event Management (SIEM) systems for enhanced detection capabilities. Remember to “de-fang” IP addresses and domains (e.g., [.] instead of .) when handling IoCs to prevent accidental resolution.
Type Indicator Description
C2 address 23[.]27[.]20[.]143:27017 Server and port listed for the October 2025 campaign.
C2 endpoint 23[.]27[.]20[.]187:80 First observed Ethereum-encoded destination.
C2 endpoint 23[.]27[.]20[.]187:443 Second observed Ethereum-encoded destination.
C2 endpoint 181[.]214[.]149[.]147:443 Third observed Ethereum-encoded destination.
C2 endpoint 181[.]214[.]149[.]148:443 Fourth observed Ethereum-encoded destination; the report also describes a port 80 dropper path on this IP.
Encoded Ethereum recipient 0x171B14bB0050171b14Bb01BB398EAAB6441Fbd47 First observed destination, encoding the port 80 C2 endpoint.
Encoded Ethereum recipient 0x171B14bb01bB171B14BB0050EB7f39C35C47E682 Second observed destination, encoding the port 443 C2 endpoint.
Encoded Ethereum recipient 0xB5D6959301bbB5D69593005000FfABa8a5A2ADA2 Third observed destination.
Encoded Ethereum recipient 0xB5D6959401bbb5D69594005000ff8C84e0b715b1 Fourth observed destination.
Ethereum signaling wallet 0x33ff3edaf55a8e03dcbc7cb40d498a49cd499891 Sender of the observed beacon transactions.
Wallet match pattern 33ff3edaf55a8e03dcbc7cb40d498a49 Partial sender address used by the scanner and detection rule.
BSC sender 0x9bc1355344b54dedf3e44296916ed15653844509 Address reported as shared with the October 2025 campaign.
BSC transaction hash 0x84e8cecd5b077eef530e7d69d546e2555199cb61759d1224d31cb31750788f62 Chain 1 payload leading to the RAT and Ethereum scanner.
BSC transaction hash 0x610c9ec972545b8df6e3aaecc7a8ab5f2f2445cf0bfbd6ee026e618d07b29e22 Chain 2 payload leading to the dropper.
TRON wallet TCqf6ZkaQD84vYsC2cuu1jRwB6JveTaRrF Chain 1 transaction pointer.
TRON wallet TFMryB9m6d4kBMRjEVyFRbqKSV1cV2NcpH Chain 2 transaction pointer.
TRON wallet TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7mAP Example wallet cited for the earlier XCTDH flow.
Aptos fallback 0x9d202c824402ca89e9aaccd2390b6f8b332ae743caa1469c695feb2781d56519 Chain 1 fallback identifier.
Aptos fallback 0x3d2075f97b7b1e3234bd653779d21c605d7d8c6ec9c98d983880be5c7f4f9471 Chain 2 fallback identifier.
XOR key 2[gWfGj;<:-93Z^C Chain 1 BSC payload decryption key, shown exactly as extracted from the report.
XOR key m6:tTh^D)cBz?NM] Chain 2 BSC payload decryption key.
XOR key ThZG+0jfXE6VAGOJ Dropper-response decryption key.
C2 path /init Port 443 endpoint returning the RAT and scanner.
C2 path /$/boot Port 80 endpoint returning the encrypted dropper.
C2 path /$/1 Port 80 endpoint returning OmniStealer.
C2 path /boot Port 443 Ethereum recovery endpoint.
Campaign marker global.i = '5-3-132' Marker in the initial code.
Version marker /*RS260605*/ Ethereum scanner marker.
Build marker B9=260924 OmniStealer build marker.
User-Agent Python-urllib/3.13 User-Agent spoofed by the Node.js loader.
HTTP header Sec-V Custom header on the dropper request.
File name config.js Example poisoned repository file in the September chain.
File name tailwind.config.js Example weaponized file in the earlier chain.
File name boot.js Script returned during Ethereum-based recovery.
RPC domain ethereum-rpc.publicnode.com Legitimate public Ethereum service named in the detection rule.
RPC domain eth.drpc.org Legitimate public Ethereum service named in the detection rule.
RPC domain blastapi.io Legitimate public Ethereum service named in the detection rule.
RPC domain bsc-dataseed.binance.org Legitimate BSC service queried by the loader.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

SilverFox Hackers Use Fake Software Sites to Distribute Malware

Next Post

New 7-Zip Installer Malware Evades Detection

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
GitHub AI Security Agent Finds 24 Android Vulnerabilities Including Account Takeover Flaws
September 29, 2026
GPT-6 Astra AI Agent Attempts Supply Chain Attacks
September 29, 2026
Threat Actors Weaponize Custom GPTs to Deliver Malware
September 29, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us