Malware payloads are hidden in BSC blockchain transaction calldata and retrieved through a TRON and Aptos indexing layer. The Ethereum recipient-address encoding described was also documented publicly as NullReceiver by OpenSourceMalware. Ransom-ISAC tracks the wider XCTDH campaign that uses it, which organizations first documented in and still track today. The analysis below is their own, and it is built on 90 days of on-chain collection. The existing attack flow involves a multi-chain resolution process: querying TRON for its latest transaction, fetching BSC transactions from the transaction hash, decoding JavaScript payloads and executing them via eval or spawned processes.
This chain requires specific TRON/Aptos wallets and BSC transactions to be reachable. HashHiding was built to solve this problem, not as another payload delivery mechanism, but as a lightweight C2 address recovery channel that can bootstrap the entire infection from scratch.[/subscribe_to_unlock_form]
Malware payloads are hidden in BSC blockchain transaction calldata and retrieved through a TRON and Aptos indexing layer. The Ethereum recipient-address encoding described was also documented publicly as NullReceiver by OpenSourceMalware. Ransom-ISAC tracks the wider XCTDH campaign that uses it, which organizations first documented in and still track today. The analysis below is their own, and it is built on 90 days of on-chain collection. The existing attack flow involves a multi-chain resolution process: querying TRON for its latest transaction, fetching BSC transactions from the transaction hash, decoding JavaScript payloads and executing them via eval or spawned processes.
This chain requires specific TRON/Aptos wallets and BSC transactions to be reachable. HashHiding was built to solve this problem, not as another payload delivery mechanism, but as a lightweight C2 address recovery channel that can bootstrap the entire infection from scratch.[emaillocker id="1283"]
The actor uses Ethereum, TRON, Aptos, and BSC together, each chain serving a distinct function: Ethereum for C2 signaling, TRON/Aptos for indexing, and BSC for payload storage. The actor keeps all three C2-resolution channels active in parallel for 90 days at a very low cost. The actor rotates the C2 address with no change to the malware code. This is a deliberate and mature use of public blockchain infrastructure.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1195 | Supply Chain Compromise | - |
| Execution | T1059.007 | Command and Scripting Interpreter | JavaScript |
| Defence Evasion | T1027.002 | Obfuscated Files or Information | Software Packing |
| Credential access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Collection | T1005 | Data from Local System | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Command and control | T1571 | Non | Standard Port- |
| Objective | Behavior ID | Behavior |
|---|---|---|
| Command & Control | B0030 | C2 Communication |
| Impact | B0022 | Remote Access |
| Discovery | E1083 | File and Directory Discovery |
| Defense Evasion | B0029 | Polymorphic Code |
| Anti-Behavioral Analysis | B0003 | Dynamic Analysis Evasion |
| Execution | E1204 | User Execution |
| Exfiltration | E1020 | Automated Exfiltration |
The following reports contain further technical details:
[/emaillocker]