Attackers Exploit Ethereum Blockchain for Covert Malware Communications
Key Takeaways A North Korea-linked threat actor is leveraging the Ethereum blockchain to conceal command-and-control (C2) server locations for its malware. The attackers embed C2 server IP addresses...
Key Takeaways
- A North Korea-linked threat actor is leveraging the Ethereum blockchain to conceal command-and-control (C2) server locations for its malware.
- The attackers embed C2 server IP addresses and ports within the recipient addresses of seemingly innocuous Ethereum transactions, a technique dubbed “HashHiding.”
- This multi-platform malware campaign targets developers through fake job offers and malicious code, installing remote access tools and credential stealers on Windows, macOS, and Linux systems.
- The use of multiple blockchain networks (Ethereum, TRON, Aptos, BNB Smart Chain) and redundant C2 communication channels enhances the malware’s resilience against detection and disruption.
- Organizations should monitor for unusual Ethereum blockchain queries and unexpected server connections, particularly from developer environments, to detect and mitigate this sophisticated threat.
Hackers Turn Ethereum into Covert Malware Communication Channel
A sophisticated malware campaign, attributed to a North Korea-linked threat group, has adopted an innovative method for maintaining communication with infected systems. Instead of storing malware directly on the Ethereum blockchain, the attackers are cleverly embedding the location of their command-and-control (C2) servers within cryptocurrency transaction data. This novel approach allows the malware to retrieve updated C2 server details discreetly.
Table Of Content
The campaign primarily targets developers, luring them with deceptive job opportunities, compromised code repositories, and malicious software packages. Execution of the tainted code leads to the installation of a potent remote access tool (RAT) and a credential stealer, capable of operating across Windows, macOS, and Linux platforms.
HashHiding: The Ethereum Obfuscation Technique
Researchers at Ransom-ISAC identified this new Ethereum-based component in September 2026 samples of the XCTDH malware. Ransom-ISAC, in a report shared with Cyber Security News (CSN), highlighted that this technique provides the malware with a robust alternative C2 channel, ensuring continued operation even if primary communication routes are compromised.
The method, which Ransom-ISAC has named “HashHiding,” ingeniously transforms the recipient address of an Ethereum transaction into a minute message. The initial four bytes of this address encode the server’s internet address, while the subsequent two bytes specify the corresponding port. Any remaining bytes within the address may contain a secondary endpoint or serve as padding. This differs significantly from previous tactics that involved embedding entire malware payloads within blockchain transaction data.
Crucially, these transactions typically involve no smart contract calls or embedded scripts. Most HashHiding transfers move zero cryptocurrency, while a few send a negligible amount to an address for which no one is expected to hold the private key. This makes the transactions appear as ordinary, low-value blockchain activity, further aiding in their stealth.
The infected malware continuously monitors transactions originating from the operator’s designated signaling wallet. It achieves this by scanning recent Ethereum blocks via public access points. Upon identifying a matching transaction, the malware decodes the recipient address to extract the hidden C2 server information and subsequently establishes contact with that server. The C2 server then delivers additional code, facilitating the re-establishment or continuation of the infection. While earlier reports described a related technique called NullReceiver for hiding malware servers in Ethereum transfers, Ransom-ISAC distinguishes this campaign due to its unique use of a blockchain address as a dynamic signpost rather than a static storage location for malicious code.
During the observed period, the threat actor altered the encoded destination four times. The first two changes directed to the same internet address but utilized different ports. Subsequent changes shifted the C2 to an entirely new address range. One notable change involved only modifying the final octet of the server’s IP address, a subtle alteration designed to evade common blocklist detections.
Multiple Paths Ensure Malware Persistence
The Ethereum component is just one facet of a multi-layered C2 infrastructure. The initial malware loader also inspects transactions on the TRON blockchain, with Aptos serving as a backup, to locate encrypted JavaScript payloads stored within BNB Smart Chain transactions. This established, older pathway delivers the core malicious code, while the newly discovered Ethereum route primarily provides dynamic updates for the C2 server location.
The attack chain commences when a developer interacts with a fraudulent recruitment advertisement and executes a compromised project or software package. As demonstrated by JavaScript loaders concealed in various repositories, such projects can harbor code that initiates communication with blockchain services upon execution. In this particular campaign, the hidden loader retrieves subsequent malware stages without relying on easily identifiable malicious download links. The updated remote access tool boasts capabilities such as command execution, keystroke logging, and clipboard monitoring.
A separate, one-time information stealer module targets a wide array of sensitive data, including browser information, password manager databases, cloud storage credentials, and cryptocurrency wallet material. Researchers documented 153 distinct cryptocurrency wallet targets, noting that stolen data is exfiltrated via a messaging bot interface.
The Ethereum scanner operates concurrently with the remote access tool, rather than activating only as a fallback mechanism. A hardcoded C2 server location and the pre-existing cross-chain communication path also remain active. This redundant design ensures that blocking a single server or a specific blockchain access point may not be sufficient to neutralize the threat, as alternative routes remain operational.
The overarching risk mirrors other developer-focused attacks that leverage blockchain for payload delivery, where a seemingly legitimate development task becomes the initial vector for compromise.
What You Should Do
- Monitor Blockchain Activity: Implement monitoring for unexpected queries to Ethereum public RPC (Remote Procedure Call) services (e.g.,
ethereum-rpc.publicnode.com,eth.drpc.org,blastapi.io) originating from internal networks, especially developer workstations. - Inspect Outbound Connections: Scrutinize outbound network connections for unusual server communications following any blockchain queries. Look for connections to the identified C2 endpoints (e.g.,
23.27.20.143:27017,181.214.149.147:443,181.214.149.148:443). - Review Developer Environments: Conduct thorough reviews of developer environments for any signs of compromise, including unexpected Node.js processes executing evaluated code.
- Implement Strong Software Supply Chain Security: Exercise extreme caution with third-party code, open-source projects, and software packages. Verify the authenticity and integrity of all development tools and libraries.
- Monitor Signaling Wallets: Keep a close watch on the identified Ethereum signaling wallet (
0x33ff3edaf55a8e03dcbc7cb40d498a49cd499891) for new transaction patterns that could indicate changes in C2 destinations. - Educate Developers: Provide continuous training to developers on social engineering tactics, particularly those involving fake job offers and poisoned code repositories.
- Utilize IoCs for Detection: Integrate the provided Indicators of Compromise (IoCs) into your threat intelligence platforms (e.g., MISP, VirusTotal) and Security Information and Event Management (SIEM) systems for enhanced detection capabilities. Remember to “de-fang” IP addresses and domains (e.g.,
[.]instead of.) when handling IoCs to prevent accidental resolution.
| Type | Indicator | Description |
|---|---|---|
| C2 address | 23[.]27[.]20[.]143:27017 |
Server and port listed for the October 2025 campaign. |
| C2 endpoint | 23[.]27[.]20[.]187:80 |
First observed Ethereum-encoded destination. |
| C2 endpoint | 23[.]27[.]20[.]187:443 |
Second observed Ethereum-encoded destination. |
| C2 endpoint | 181[.]214[.]149[.]147:443 |
Third observed Ethereum-encoded destination. |
| C2 endpoint | 181[.]214[.]149[.]148:443 |
Fourth observed Ethereum-encoded destination; the report also describes a port 80 dropper path on this IP. |
| Encoded Ethereum recipient | 0x171B14bB0050171b14Bb01BB398EAAB6441Fbd47 |
First observed destination, encoding the port 80 C2 endpoint. |
| Encoded Ethereum recipient | 0x171B14bb01bB171B14BB0050EB7f39C35C47E682 |
Second observed destination, encoding the port 443 C2 endpoint. |
| Encoded Ethereum recipient | 0xB5D6959301bbB5D69593005000FfABa8a5A2ADA2 |
Third observed destination. |
| Encoded Ethereum recipient | 0xB5D6959401bbb5D69594005000ff8C84e0b715b1 |
Fourth observed destination. |
| Ethereum signaling wallet | 0x33ff3edaf55a8e03dcbc7cb40d498a49cd499891 |
Sender of the observed beacon transactions. |
| Wallet match pattern | 33ff3edaf55a8e03dcbc7cb40d498a49 |
Partial sender address used by the scanner and detection rule. |
| BSC sender | 0x9bc1355344b54dedf3e44296916ed15653844509 |
Address reported as shared with the October 2025 campaign. |
| BSC transaction hash | 0x84e8cecd5b077eef530e7d69d546e2555199cb61759d1224d31cb31750788f62 |
Chain 1 payload leading to the RAT and Ethereum scanner. |
| BSC transaction hash | 0x610c9ec972545b8df6e3aaecc7a8ab5f2f2445cf0bfbd6ee026e618d07b29e22 |
Chain 2 payload leading to the dropper. |
| TRON wallet | TCqf6ZkaQD84vYsC2cuu1jRwB6JveTaRrF |
Chain 1 transaction pointer. |
| TRON wallet | TFMryB9m6d4kBMRjEVyFRbqKSV1cV2NcpH |
Chain 2 transaction pointer. |
| TRON wallet | TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7mAP |
Example wallet cited for the earlier XCTDH flow. |
| Aptos fallback | 0x9d202c824402ca89e9aaccd2390b6f8b332ae743caa1469c695feb2781d56519 |
Chain 1 fallback identifier. |
| Aptos fallback | 0x3d2075f97b7b1e3234bd653779d21c605d7d8c6ec9c98d983880be5c7f4f9471 |
Chain 2 fallback identifier. |
| XOR key | 2[gWfGj;<:-93Z^C |
Chain 1 BSC payload decryption key, shown exactly as extracted from the report. |
| XOR key | m6:tTh^D)cBz?NM] |
Chain 2 BSC payload decryption key. |
| XOR key | ThZG+0jfXE6VAGOJ |
Dropper-response decryption key. |
| C2 path | /init |
Port 443 endpoint returning the RAT and scanner. |
| C2 path | /$/boot |
Port 80 endpoint returning the encrypted dropper. |
| C2 path | /$/1 |
Port 80 endpoint returning OmniStealer. |
| C2 path | /boot |
Port 443 Ethereum recovery endpoint. |
| Campaign marker | global.i = '5-3-132' |
Marker in the initial code. |
| Version marker | /*RS260605*/ |
Ethereum scanner marker. |
| Build marker | B9=260924 |
OmniStealer build marker. |
| User-Agent | Python-urllib/3.13 |
User-Agent spoofed by the Node.js loader. |
| HTTP header | Sec-V |
Custom header on the dropper request. |
| File name | config.js |
Example poisoned repository file in the September chain. |
| File name | tailwind.config.js |
Example weaponized file in the earlier chain. |
| File name | boot.js |
Script returned during Ethereum-based recovery. |
| RPC domain | ethereum-rpc.publicnode.com |
Legitimate public Ethereum service named in the detection rule. |
| RPC domain | eth.drpc.org |
Legitimate public Ethereum service named in the detection rule. |
| RPC domain | blastapi.io |
Legitimate public Ethereum service named in the detection rule. |
| RPC domain | bsc-dataseed.binance.org |
Legitimate BSC service queried by the loader. |
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.