A DPRK-linked XCTDH campaign targeting cryptocurrency and software developers has added an Ethereum-based command-and-control recovery mechanism, HashHiding, to its existing multichain infrastructure. Malware scans transactions from a designated Ethereum signal wallet and decodes a replacement C2 IPv4 address and port from the recipient address of ordinary coin transfers, allowing operators to rotate infrastructure without updating malware. Researchers observed 2,655 Ethereum beacon transactions and four C2 rotations; HashHiding operates alongside hardcoded C2 servers and a TRON/Aptos-to-BNB Smart Chain payload-resolution chain.
The operators use fake job offers, poisoned GitHub repositories, and trojanized NPM packages to deliver the Node.js-based DEV#POPPER.js RAT and OmniStealer credential harvester across Windows, macOS, and Linux. The RAT can execute commands and collect keystrokes and clipboard data, while OmniStealer targets browser, password-manager, cloud-storage, and cryptocurrency-wallet data. The activity reflects broader adoption of blockchain dead drops—public-chain transactions, smart contracts, or wallets used to carry C2 instructions or payload pointers—by DPRK, Iranian, and criminal operators, making conventional server blocklisting insufficient without detecting the initial developer-targeting infection chain and blockchain-resolution behavior.

TTPs, infrastructure, and targeting history in one profile.
12 events from the most recent confirmed update back to the earliest known activity.
During the approximately 90-day Ethereum collection period, researchers observed four encoded C2 rotations, including endpoints at 23[.]27[.]20[.]187 and 181[.]214[.]149[.]147-148. The signaling transactions continued through September 21.
Chainalysis published research describing Blockchain Dead Drops, including blockchain-resident C2 data and payload pointers used by DPRK-linked UNC5342, Iranian-linked actors, and Russian-speaking malware-as-a-service operators.
September XCTDH samples added the _Z JavaScript module, which scans Ethereum transactions from a signal wallet and decodes an IP address and port from recipient-address bytes. The mechanism ran alongside hardcoded C2 infrastructure and the existing TRON/Aptos-to-BNB Smart Chain delivery path.
The Ethereum wallet identified as the XCTDH signaling wallet began sending beacon transactions used to convey encoded C2 destinations. Researchers later counted 2,655 outbound transactions through September 21.
A developer was targeted in a fake recruitment process using LinkedIn outreach and a Google Meet interview, culminating in a request to run the malicious ArsagaPPro/Jp-Soccer2 GitHub repository. Opening the repository as trusted in VS Code could silently run a task that deployed a Node.js remote-code-execution payload.
The DPRK-linked XCTDH operation was first publicly documented, using a cross-chain delivery design associated with a BNB Smart Chain sender later retained by the campaign.
Actors linked to Iran's Ministry of Intelligence reportedly encoded C2 routing data in Bitcoin OP_RETURN transactions and rotated infrastructure through new transactions.
The Smargaft DDoS botnet reportedly used a BNB Smart Chain smart contract for command-and-control.
ClearFake operators deployed the EtherHiding technique on BNB Smart Chain, using contract-based blockchain storage for malicious infrastructure.
The Glupteba botnet used Bitcoin OP_RETURN fields to store C2-related data.
Threat actors encoded C2 IP addresses in Bitcoin satoshi amounts, demonstrating transaction-based blockchain C2 signaling.
A Necurs botnet variant reportedly stored command-and-control domains in the Namecoin blockchain.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 45 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecyberveille.ch
Open sourceransom-isac.org
Open sourceransom-isac.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.