Omnistealer: DPRK-Linked Blockchain-Based Infostealer Abusing TRON/Aptos/BSC as Resilient C2 to Loot Password Managers, Browser Credentials, Cloud Storage, and 60+ Crypto Wallets — Threadlinqs Intelligence
As of 2026-05-30, Omnistealer: DPRK-Linked Blockchain-Based Infostealer Abusing TRON/Aptos/BSC as Resilient C2 to Loot Password Managers, Browser Credentials, Cloud Storage, and 60+ Crypto Wallets is a high-severity malware threat attributed to Suspected DPRK (North Korea), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 45 indicators of compromise.
Threat ID: TL-2026-0360 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Suspected DPRK · North Korea · FINANCIAL
Omnistealer is an actively distributed, multi-stage infostealer tied to suspected DPRK-aligned operators who approach software developers with fake LinkedIn/Upwork job offers that drop malicious
Omnistealer (also tracked as the Cross-Chain TxDataHiding campaign) is a cross-platform JavaScript/Python infostealer and modular RAT first publicly documented by Malwarebytes Labs, Ransom-ISAC, and Dataconomy in late March and April 2026. The operation is being run through a fake-recruiter pipeline aimed primarily at freelance and full-stack developers: attackers pose as hiring managers on LinkedIn and Upwork, move candidates to Telegram or Discord, then send them a ''coding test'' hosted in a private GitHub repository. The trojanized project (most often a Tailwind/Next.js frontend such as github.com/isasmallbit/store-v) embeds a hostile Tailwind.config.js or next.config.mjs that runs on install.
The dropper is deliberately engineered for takedown resistance. Stage 1 is a heavily obfuscated JavaScript stager that pulls a cross-chain lookup list from attacker-controlled TRON addresses (TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7mAP, TXfxHUet9pJVU1BgVkBAbrES4YUc1nGzcG, TLmj13VL4p6NQ7jpxz8d9uYY6FUKCYatSe), with fallback indices on Aptos (0xbe03..0811e, 0x3f0e..5dce3, 0x3414..05837). The index data points at specific Binance Smart Chain transaction hashes (0xf46c..19fc, 0xd33f..58fef, 0xa8cd..16ff) whose input fields carry the XOR-encrypted next-stage payload. Because the loader reads data directly from public RPC endpoints (api.trongrid.io, fullnode.mainnet.aptoslabs.com, bsc-dataseed.binance.org), defenders cannot seize or sinkhole the configuration channel — transactions are immutable and geographically unreachable by traditional takedown.
Stage 2 decrypts a cross-platform Python RAT (Payload1_1_1) and a Python dropper (Payload1_2_1) that fetches the final Omnistealer payload (Payload1_2_1_1). The RAT pivots to one of four hardcoded MongoDB-port (27017) C2 servers — 23.27.20.143, 136.0.9.8, 23.27.202.27, and 166.88.4.2 — using a _V routing byte to decide which operator node receives a given victim. HTTP endpoints /$/boot, /$/z1, /u/f, /u/e, /snv, and /verify-human/{version} handle delivery, file exfiltration, metadata, and environment-variable theft. A Telegram bot (token 7870147428:AAGbYG_eYkiAziCKRmkiQF-GnsGTic_3TTU) is hard-wired as a backup exfiltration channel whenever outbound HTTP to the primary C2 is blocked.
Omnistealer''s credential-collection surface is unusually broad. Targeted password managers include 1Password (aeblfdkhhhdcdjpifhhbdiojplfjncoa), LastPass (hdokiejnpimakedhajhdlcegeplioahd), Dashlane (fdjamakpfbbddfjaooikfcpapjohcfmg), NordPass (eiaeiblijfjekdanodkjadfinkhbfgcd), and Bitwarden (nngceckbapebfimnlniiiahkandclblb). Targeted wallet extensions include MetaMask (nkbihfbeogaeaoehlefnkodbefgpgknn), Phantom (bfnaelmomeimhlpmgjnjophhpkkoljpa), Trust (egjidjbpglichdcondbcbdnbeeppgdph), Coinbase (hnfanknocfeofbddgcijnmhnfnkdnaad), TronLink (ibnejdfjmmkpcnlpebklmnkoeoihofec), Xverse (idnnbdplmphpflfnlkomgpfbpcgelopg), Keplr (dmkamcknogkgcdfhhbddcghachkejeap), and Rabby (acmacodkjbdgmoleebolmdjonilkdbch), plus desktop wallets (Exodus, Atomic, Electrum, Bitcoin Core, Monero, Solana CLI). Chrome, Edge, Brave, Firefox, Opera, Opera GX, Vivaldi, Arc, and Chromium are all scraped for saved logins and cookies. The stealer also enumerates Dropbox, Google Drive, OneDrive, iCloud, Box, Mega, and pCloud client state.
Persistence is established through targeted JavaScript injection into VSCode and Cursor IDE installations — specifically the @vscode/deviceid module — marked with a /*C250617A*/ comment header to prevent re-injection. The Cursor injection is particularly notable because AI-assisted coding IDEs execute user code in a higher-trust context, effectively backdooring the developer''s entire toolchain. Evasion logic blocks execution in AWS EC2, Azure, GCP, Vercel, Amplify, GitHub Actions runners, Docker containers, Kali Linux, and the test hostname EV-CHQG3L42MMQ. A catastrophic-backtracking regex (.search("(((.+)+)+)+$")) is used as an anti-debugger tripwire.
Exfiltrated data is packaged into password-protected ZIP archi
Weaknesses (CWE)
CWE-506, CWE-829, CWE-494
Target sectors: technology, software-development, cryptocurrency, defense, government, financial, food-delivery, adult-industry, freelance-platforms
Target regions: Global, North America, Europe, South Asia, South Korea, United States
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 45 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583, T1583, T1585, T1586, T1566, T1195, T1059, T1059, T1204, T1547