A DPRK-linked malware campaign now hides its command-and-control (C2) address in the destination field of ordinary Ethereum transactions. Ransom-ISAC calls the technique HashHiding, and it gives the operators a recovery channel that is very hard to block.
Ransom-ISAC first documented the Cross-Chain TxDataHiding (XCTDH) campaign in October 2025. Nearly a year later, it is still live and has changed very little.
The September 2026 samples add Ethereum as a fourth blockchain, alongside TRON, Aptos and BSC. Researchers Ellis Stannard and Nick Smart built their analysis on 90 days of on-chain collection.
DPRK XCTDH Malware Uses Ethereum “HashHiding”
The first beacon appeared on 23 June 2026, several weeks before OpenSourceMalware publicly described the same encoding as NullReceiver in August 2026. Ransom-ISAC credits that team for the technique and the name.
Earlier XCTDH stages hid large encrypted payloads in BSC transaction calldata, reached through a TRON and Aptos indexing layer. HashHiding carries no payload.

It encodes six bytes- an IPv4 address and a port- in the “to” field of a plain coin transfer. The first four bytes are the IP, and the next two are the port. For example, 0xB5D69594 01bb decodes to 181.214.149.148 on port 443.
The recipient wallets are fabricated, so nobody holds their private keys. Most transfers send 0 wei, and a few send 150 wei. There are no smart contracts to delist and no funded wallets to freeze.
Researchers found the technique inside _Z, a 69,470-character JavaScript module returned by the C2’s /init endpoint. Base-91 string encoding with 18 custom alphabets and generator-based control-flow flattening protected it. Once deobfuscated, it shrinks to 8,777 bytes of code that does one job.
A random public Ethereum RPC provider then searches backward through blocks at exponentially growing offsets. It looks for transactions from the operator’s Signal wallet, decodes the C2 from the “to” address, fetches /boot, and spawns the response as a new detached Node.js process.
The DEV#POPPER.js RAT launches _Z unconditionally. It is not a fallback that waits for other channels to fail.

The signal wallet sent 2,655 transactions between 23 June and 21 September 2026, roughly one every 49 minutes. The operator rotated the encoded C2 four times:
| Period | Decoded C2 | Beacons |
|---|---|---|
| 23–24 Jun | 23[.]27[.]20[.]187:80 | 55 |
| 24 Jun–3 Sep | 23[.]27[.]20[.]187:443 | 1,987 |
| 3–7 Sep | 181[.]214[.]149[.]147:443 | 111 |
| 7–21 Sep | 181[.]214[.]149[.]148:443 | 502 |
The last change moved the final octet from 147 to 148, a single hex step from 0x93 to 0x94. Researchers say a near-identical successor could slip past manual review and blocklists that hold only the previous address.
The campaign runs three C2 resolution paths at once: a hardcoded IP, the TRON/Aptos-to-BSC chain, and HashHiding. Defenders must therefore cut all three at once. The BSC contract (0x9bc1355…) and the XOR key.
Victims typically arrive through fake job offers on Telegram, which lead to weaponized GitHub repositories or trojanised NPM packages. The RAT is followed by OmniStealer, a Python credential harvester that targets 153 wallets plus browsers, password managers, and cloud storage. It exfiltrates data through the Telegram bot API and does not persist.
Blocking one IP is not enough. Teams should block the historic and current C2 addresses, including 23[.]27[.]20[.]187 and 181[.]214[.]149[.]147/148. They should also monitor for unexpected Ethereum RPC traffic from developer machines and treat unsolicited coding “interviews” as a hostile entry point.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.