DPRK-linked operators behind the Cross-Chain TxDataHiding (XCTDH) campaign have expanded their blockchain-backed command-and-control infrastructure with a new Ethereum-based recovery channel dubbed HashHiding.
The technique stores an active C2 IP address and port inside the recipient address of ordinary Ethereum transfers, allowing infected systems to recover attacker infrastructure without relying on domains, smart contracts, or transaction calldata.
The current activity preserves that three-chain architecture while adding Ethereum as a lightweight C2-signaling layer, creating a four-blockchain system designed to withstand conventional disruption efforts.
The newly identified JavaScript component, _Z, was found in a September 2026 /init response delivered by the campaign’s existing BSC payload chain.
After deobfuscation, the approximately 69,470-character module was reduced to code that scans Ethereum mainnet blocks for transactions sent by a hardcoded signal wallet: 0x33ff3edaf55a8e03dcbc7cb40d498a49cd499891.
Rather than putting malicious code in a transaction’s input field, HashHiding encodes just six bytes an IPv4 address and port into the first bytes of the Ethereum to address.
For example, the recipient address 0xB5D6959401bbb5D69594005000ff8C84e0b715b1 decodes to 181[.]214[.]149[.]148:443. The remaining bytes contain a secondary endpoint and padding.
This architecture resembles the recipient-address technique publicly documented as NullReceiver in August 2026.
That research showed DPRK-linked npm malware extracting its C2 location from zero-value Ethereum transfer recipients rather than smart-contract storage or calldata.
Ransom-ISAC’s tracking, however, places the first observed beacon associated with this wider XCTDH campaign on June 23, 2026 weeks before the public NullReceiver disclosure.
HashHiding is not a replacement for Cross-Chain TxDataHiding. The two methods serve different roles.
XCTDH hides large encrypted payloads in BSC transaction calldata, while TRON and Aptos provide indirection by carrying the BSC transaction hashes.
HashHiding carries only a live C2 endpoint, enabling malware to bootstrap or re-bootstrap its communication channel.
The September samples show three C2-resolution paths operating in parallel: a hardcoded endpoint, the TRON/Aptos-to-BSC payload chain, and Ethereum-based HashHiding.
Ransom-ISAC first documented the wider campaign in October 2025, describing how malware used TRON and Aptos as pointer layers to retrieve transaction hashes for encrypted payloads embedded in BSC transaction calldata.
The Ethereum scanner selects public RPC services, retrieves a recent block number, searches backward using exponential offsets, locates a transfer from the signal wallet, decodes the destination address, and fetches /boot from the recovered server.
The approach makes address rotation inexpensive. Instead of distributing updated malware or changing a domain, the operator can send another low-value Ethereum transaction to a fabricated recipient address that encodes a replacement IP and port.
The campaign continues to use social engineering against developers, including Telegram-based fake job offers, weaponized GitHub repositories, trojanized npm packages, and malicious configuration files padded with whitespace to conceal appended JavaScript.
Earlier analysis linked the operation to a Node.js RAT called DEV#POPPER.js and the Python-based OmniStealer credential harvester.
The updated /init endpoint returns four components: _U, the C2 base URL; _H, bootstrap code; _B, the DEV#POPPER RAT; and _Z, the HashHiding scanner.
_B launches _Z as a detached background process rather than reserving it as a failover mechanism. This means the Ethereum channel begins operating immediately and independently on every compromised host.
DEV#POPPER now provides WebSocket C2 communications, command execution, shell spawning, clipboard monitoring, keylogging, and IDE-focused persistence.
Separately, the campaign’s dropper chain installs Python and retrieves OmniStealer, which targets browser data, password managers, cloud-storage credentials, and 153 cryptocurrency-wallet targets.
On-chain activity shows 2,655 outbound beacon transactions from the Ethereum signal wallet between June 23 and September 21, 2026.
Observed C2 endpoints include 23[.]27[.]20[.]187 on ports 80 and 443, 181[.]214[.]149[.]147:443, and 181[.]214[.]149[.]148:443.
Defenders should hunt for Node.js processes making unexplained JSON-RPC requests to Ethereum, TRON, Aptos, or BSC providers; investigate JavaScript that calls eth_getTransactionByHash; and monitor outbound traffic from developer environments to the listed IPs.
The persistent BSC infrastructure address 0x9bc1355344b54dedf3e44296916ed15653844509 and the Ethereum signal wallet should also be tracked as high-confidence indicators.
| Endpoint | Port | Returns |
|---|---|---|
/init | 443 | 303KB JSON containing _B (the RAT) and _Z (the HashHiding scanner) |
/$/boot | 80 | XOR-encrypted Dropper (installs Python 3.13 and 7-Zip, fetches OmniStealer) |
/$/1 | 80 | XOR-encrypted OmniStealer |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…