Threat Advisory

DPRK Campaign Uses Ethereum Mainnet for C2 Address Distribution

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Malware payloads are hidden in BSC blockchain transaction calldata and retrieved through a TRON and Aptos indexing layer. The Ethereum recipient-address encoding described was also documented publicly as NullReceiver by OpenSourceMalware. Ransom-ISAC tracks the wider XCTDH campaign that uses it, which organizations first documented in and still track today. The analysis below is their own, and it is built on 90 days of on-chain collection. The existing attack flow involves a multi-chain resolution process: querying TRON for its latest transaction, fetching BSC transactions from the transaction hash, decoding JavaScript payloads and executing them via eval or spawned processes.

This chain requires specific TRON/Aptos wallets and BSC transactions to be reachable. HashHiding was built to solve this problem, not as another payload delivery mechanism, but as a lightweight C2 address recovery channel that can bootstrap the entire infection from scratch.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Malware payloads are hidden in BSC blockchain transaction calldata and retrieved through a TRON and Aptos indexing layer. The Ethereum recipient-address encoding described was also documented publicly as NullReceiver by OpenSourceMalware. Ransom-ISAC tracks the wider XCTDH campaign that uses it, which organizations first documented in and still track today. The analysis below is their own, and it is built on 90 days of on-chain collection. The existing attack flow involves a multi-chain resolution process: querying TRON for its latest transaction, fetching BSC transactions from the transaction hash, decoding JavaScript payloads and executing them via eval or spawned processes.

This chain requires specific TRON/Aptos wallets and BSC transactions to be reachable. HashHiding was built to solve this problem, not as another payload delivery mechanism, but as a lightweight C2 address recovery channel that can bootstrap the entire infection from scratch.[emaillocker id="1283"]

The actor uses Ethereum, TRON, Aptos, and BSC together, each chain serving a distinct function: Ethereum for C2 signaling, TRON/Aptos for indexing, and BSC for payload storage. The actor keeps all three C2-resolution channels active in parallel for 90 days at a very low cost. The actor rotates the C2 address with no change to the malware code. This is a deliberate and mature use of public blockchain infrastructure.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1195 Supply Chain Compromise -
Execution T1059.007 Command and Scripting Interpreter JavaScript
Defence Evasion T1027.002 Obfuscated Files or Information Software Packing
Credential access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols
Command and control T1571 Non Standard Port-

MBC MAPPING:

Objective Behavior ID Behavior
Command & Control B0030 C2 Communication
Impact B0022 Remote Access
Discovery E1083 File and Directory Discovery
Defense Evasion B0029 Polymorphic Code
Anti-Behavioral Analysis B0003 Dynamic Analysis Evasion
Execution E1204 User Execution
Exfiltration E1020 Automated Exfiltration

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu