Hackers Turned Ethereum Into a Secret Messaging System for Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A North Korea-linked malware campaign has found a way to keep infected computers connected to its operators. Instead of storing malware on Ethereum, the attackers hide the location of a control server inside cryptocurrency transfers.

The campaign reaches developers through fake job offers, tainted code repositories and malicious software packages. Running the code can install a remote access tool and a credential stealer across Windows, macOS and Linux.

Researchers from Ransom-ISAC identified the new Ethereum component in September 2026 samples of XCTDH.

Ransom-ISAC said in a report shared with Cyber Security News (CSN) that the technique gives the malware another way to find its operator if other routes are disrupted.

The operation was first documented in October 2025, but the researchers found its Ethereum signals began in June 2026. They counted 2,655 transactions over 90 days. The report does not establish how many computers were infected or how much data was stolen.

Hackers Turned Ethereum Into a Secret Messaging System

The method, called HashHiding by Ransom-ISAC, turns the recipient address of an Ethereum transfer into a tiny message. Its first four bytes represent the server’s internet address, and the next two represent its port.

The remaining bytes contain a second endpoint and padding. That is different from placing full malware payloads in blockchain transaction data.

These transfers carry no smart contract call or hidden script. Most move no cryptocurrency, while a few transfer a tiny amount to an address whose private key nobody is expected to control.

The malware watches transactions sent from the operator’s signaling wallet. It scans recent Ethereum blocks through public access points, finds a matching transfer, decodes its recipient address and contacts the server it reveals.

The server then supplies code that can rebuild the infection. Earlier reporting on malware servers hidden inside Ethereum transfers described a related method called NullReceiver.

Kill Chain (Source - Ransom-ISAC)
Kill Chain (Source – Ransom-ISAC)

Ransom-ISAC credits that earlier public description, while tracing this separate campaign through its own on-chain collection. The distinction matters because a blockchain address here acts as a signpost, not a storage site for malware.

The operator changed the encoded destination four separate times during the observed period. The first two signals pointed to the same internet address on different ports; later signals moved to another address range. One subsequent change altered only the final number of the server address, a shift that could escape blocklists.

Multiple Paths Keep Malware Connected

Ethereum is only one part of this operation. The initial loader checks transactions on TRON, with Aptos as a backup, to locate encrypted JavaScript stored in BNB Smart Chain transactions. That older route delivers code, while the Ethereum route supplies a fresh server location.

The attack begins when a developer follows a fake recruitment prompt and runs a poisoned project or package. As JavaScript loaders hidden in repositories have shown, a project can carry code that contacts blockchain services after execution.

Here, the hidden loader brings in later stages without an obvious malicious download link. The updated remote access tool can run commands, record keystrokes and watch the clipboard.

A separate one-time stealer seeks browser information, password manager data, cloud storage credentials and cryptocurrency wallet material. Researchers counted 153 wallet targets and said stolen data leaves through a messaging bot interface.

The Ethereum scanner starts alongside the remote access tool, not only after a connection fails. A hardcoded server location and the older cross-chain path also remain active. This parallel design means blocking one server or one blockchain access point may leave another route open.

The broader risk resembles developer attacks using blockchain payloads, where a trusted-looking development task becomes the first step of compromise.

Ransom-ISAC recommends watching for unexpected Ethereum block queries followed by unusual server connections and monitoring the signaling wallet for new destination changes.

Teams investigating a suspected infection should also examine Node.js processes running evaluated code and review developer environments.

Removing a known server alone is not enough if the malware can read a newer server address from public blockchain records and start the chain again.

Indicators of compromise (IoCs):-

Type Indicator Description
C2 address 23[.]27[.]20[.]143:27017 Server and port listed for the October 2025 campaign.
C2 endpoint 23[.]27[.]20[.]187:80 First observed Ethereum-encoded destination.
C2 endpoint 23[.]27[.]20[.]187:443 Second observed Ethereum-encoded destination.
C2 endpoint 181[.]214[.]149[.]147:443 Third observed Ethereum-encoded destination.
C2 endpoint 181[.]214[.]149[.]148:443 Fourth observed Ethereum-encoded destination; the report also describes a port 80 dropper path on this IP.
Encoded Ethereum recipient 0x171B14bB0050171b14Bb01BB398EAAB6441Fbd47 First observed destination, encoding the port 80 C2 endpoint.
Encoded Ethereum recipient 0x171B14bb01bB171B14BB0050EB7f39C35C47E682 Second observed destination, encoding the port 443 C2 endpoint.
Encoded Ethereum recipient 0xB5D6959301bbB5D69593005000FfABa8a5A2ADA2 Third observed destination.
Encoded Ethereum recipient 0xB5D6959401bbb5D69594005000ff8C84e0b715b1 Fourth observed destination.
Ethereum signaling wallet 0x33ff3edaf55a8e03dcbc7cb40d498a49cd499891 Sender of the observed beacon transactions.
Wallet match pattern 33ff3edaf55a8e03dcbc7cb40d498a49 Partial sender address used by the scanner and detection rule.
BSC sender 0x9bc1355344b54dedf3e44296916ed15653844509 Address reported as shared with the October 2025 campaign.
BSC transaction hash 0x84e8cecd5b077eef530e7d69d546e2555199cb61759d1224d31cb31750788f62 Chain 1 payload leading to the RAT and Ethereum scanner.
BSC transaction hash 0x610c9ec972545b8df6e3aaecc7a8ab5f2f2445cf0bfbd6ee026e618d07b29e22 Chain 2 payload leading to the dropper.
TRON wallet TCqf6ZkaQD84vYsC2cuu1jRwB6JveTaRrF Chain 1 transaction pointer.
TRON wallet TFMryB9m6d4kBMRjEVyFRbqKSV1cV2NcpH Chain 2 transaction pointer.
TRON wallet TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7mAP Example wallet cited for the earlier XCTDH flow.
Aptos fallback 0x9d202c824402ca89e9aaccd2390b6f8b332ae743caa1469c695feb2781d56519 Chain 1 fallback identifier.
Aptos fallback 0x3d2075f97b7b1e3234bd653779d21c605d7d8c6ec9c98d983880be5c7f4f9471 Chain 2 fallback identifier.
XOR key 2[gWfGj;<:-93Z^C Chain 1 BSC payload decryption key, shown exactly as extracted from the report.
XOR key m6:tTh^D)cBz?NM] Chain 2 BSC payload decryption key.
XOR key ThZG+0jfXE6VAGOJ Dropper-response decryption key.
C2 path /init Port 443 endpoint returning the RAT and scanner.
C2 path /$/boot Port 80 endpoint returning the encrypted dropper.
C2 path /$/1 Port 80 endpoint returning OmniStealer.
C2 path /boot Port 443 Ethereum recovery endpoint.
Campaign marker global.i = '5-3-132' Marker in the initial code.
Version marker /*RS260605*/ Ethereum scanner marker.
Build marker B9=260924 OmniStealer build marker.
User-Agent Python-urllib/3.13 User-Agent spoofed by the Node.js loader.
HTTP header Sec-V Custom header on the dropper request.
File name config.js Example poisoned repository file in the September chain.
File name tailwind.config.js Example weaponized file in the earlier chain.
File name boot.js Script returned during Ethereum-based recovery.
RPC domain ethereum-rpc.publicnode.com Legitimate public Ethereum service named in the detection rule.
RPC domain eth.drpc.org Legitimate public Ethereum service named in the detection rule.
RPC domain blastapi.io Legitimate public Ethereum service named in the detection rule.
RPC domain bsc-dataseed.binance.org Legitimate BSC service queried by the loader.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Hackers Turned Ethereum Into a Secret Messaging System for Malware appeared first on Cyber Security News.