EtherHiding / Blockchain Dead Drops: Nation-State Actors Drive 440% Surge in On-Chain Malware C2
EtherHiding / Blockchain Dead Drops (TL-2026-2547), also tracked as Blockchain Dead Drops, is a high-severity malware campaign, first published 2026-09-17. It is attributed to UNC5342 (North Korea) with high confidence, affects npm (JavaScript ecosystem) Trojanized packages impersonating Tailwind, maps to 17 MITRE ATT&CK techniques (T1005, T1027, T1059.006), and is covered by 9 detection rules and 29 indicators of compromise.
Key facts for TL-2026-2547
- Threat ID
- TL-2026-2547
- Also known as
- Blockchain Dead Drops, BDD, EtherHiding, NullReceiver
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-09-17
- Last reviewed
- 2026-09-17
- Attribution
- UNC5342
- Attribution confidence
- HIGH
- Nation-state nexus
- North Korea
- Motivation
- FINANCIAL
- Target sectors
- technology, software-development, cryptocurrency, finance, blockchain
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 29
Malware and tooling in EtherHiding / Blockchain Dead Drops
Malware and tooling: ACR Stealer, BeaverTail - S1246, ClearFake, InvisibleFerret - S1245, JADESNOW, NullReceiver, Okobot, SectopRAT, Smargaft, Vidar, ErrTraffic
Chainalysis reports a 440% surge in malicious blockchain writes since mid-2025 (2.06/day to 11.1/day) as nation-state actors adopt 'blockchain dead drops' (BDD) — storing malware payloads and C2 configuration directly in smart contracts and transactions across BNB Smart Chain, Ethereum, Polygon, TRON, Aptos, and Bitcoin to build takedown-resistant infrastructure. DPRK's UNC5342 pioneered state-backed use of the EtherHiding technique in its Contagious Interview campaign (JADESNOW/InvisibleFerret/BeaverTail), Iran's Ministry of Intelligence writes C2 routing data into Bitcoin OP_RETURN fields, and Russian-language criminals sell EtherHiding-based dead-drop C2 as a service (ErrTraffic), with nation-state actors now responsible for roughly two-thirds of new activity as of Q2 2026.
How EtherHiding / Blockchain Dead Drops works
'Blockchain dead drops' (BDD) describes a growing class of techniques in which threat actors write malware payloads, command-and-control (C2) configuration, or infrastructure pointers directly into public blockchain transactions or smart contract state, so infected devices can retrieve instructions on demand from infrastructure that cannot be seized, sinkholed, or taken down by law enforcement or hosting providers. Chainalysis documents that malicious on-chain writes rose 440% since mid-2025 (from 2.06 to 11.1 per day, a 420% increase over the trailing 12 months), and that state-linked groups now account for roughly two-thirds of new BDD activity and half of total activity by Q2 2026 — up from a landscape dominated almost entirely by financially motivated cybercriminals through early 2024.
The technique traces to mid-2023, when operators behind the ClearFake fake-browser-update campaign (tracked by Google as UNC5142) began storing obfuscated JavaScript in Binance Smart Chain (BSC) smart contracts after Cloudflare disrupted their prior server infrastructure — the first large-scale use of what Guardio Labs later named 'EtherHiding.' In April 2024, APNIC documented the Smargaft botnet (a portmanteau of 'smart contract' and the Gafgyt IoT botnet family) using BSC RPC queries to retrieve a rotating C2 IP for DDoS attacks and SOCKS5 proxying. By 2026, Trend Micro observed ClearFake operators using four coordinated BSC testnet contracts (a stage-1 dispatcher, OS-specific ClickFix payload contracts for Windows and macOS, and an execution tracker, all deployed from wallet 0xd71f4cdC84420d2bd07F50787B4F998b4c2d5290) to deliver SectopRAT and ACRStealer via fake CAPTCHA/ClickFix lures on compromised websites — using free testnet tokens so the C2 costs nothing to operate.
In February 2025, Google Threat Intelligence Group (GTIG) observed DPRK-linked UNC5342 (also tracked as TraderTraitor, DeceptiveDevelopment, DEV#POPPER, Famous Chollima, Gwisin Gang, Tenacious Pungsan, Void Dokkaebi, and CL-STA-0240) adopt EtherHiding inside its long-running 'Contagious Interview' campaign — the first documented state-backed use of the technique. UNC5342 poses as recruiters on LinkedIn, Discord, and Telegram (using front entities such as BlockNovas LLC, Angeloper Agency, and SoftGlide LLC) and lures software/blockchain developers into running a fake technical-assessment repository. This drops the JADESNOW JavaScript downloader, which issues read-only eth_call JSON-RPC requests (via providers including Binplorer, Blockchair, Blockcypher, and Ethplorer) to a BSC smart contract (0x8eac3198dd72f3e07108c4c7cff43108ad48a71c, operated from owner address 0x9bc1355344b54dedf3e44296916ed15653844509, updated 20+ times in four months at roughly $1.37 per update) to fetch a base64/XOR-encoded second stage. That stage queries Ethereum transactions sent to the burn address 0x000...dEaD as a 'dead drop resolver' to retrieve the INVISIBLEFERRET JavaScript backdoor (arbitrary command execution, host enumeration, file exfiltration over port 3306) and, for higher-value targets, a Python variant plus BeaverTail — a credential/crypto-wallet stealer targeting MetaMask, Phantom, browser-stored passwords and credit cards, and 1Password data, exfiltrated as ZIP archives to attacker infrastructure and Telegram.
In August 2026, researchers identified NullReceiver, a stealthier DPRK evolution distributed through trojanized npm packages impersonating Tailwind CSS plugins (bianira-ui@1.27.0, fluid-type-ui@2.0.8, and related packages: post-css-transfer, scrollbar-hide-plugin, tailwind-anim, tailwind-animation-founder, tailwindcss-anim). Rather than a smart contract, NullReceiver looks up the most recent outbound transaction from a hardcoded attacker wallet (0xa322e5f3d311d3080e6f0121063e9adc2490ef1a) and decodes a C2 IP directly from the first four bytes of the zero-value, zero-data destination address (e.g., destination 0xa658863ea658863e68656c6c6f6970626f742121 decodes to 166.88.134.62) — eliminating the smart-contract interactions, payload fields, and fixed addresses that made EtherHiding detectable, while remaining tied to reused DPRK wallet infrastructure shared with the PolinRider campaign across npm, Go, and PHP ecosystems.
Outside DPRK, Chainalysis attributes activity suspected to be linked to Iran's Ministry of Intelligence and Security writing encoded C2 routing data into Bitcoin OP_RETURN fields via small payments to a widely known, historically Satoshi-linked address, active since late 2024. Separately, a Russian-language actor using the handle 'LenAI' has since December 2025 advertised ErrTraffic, a malware-as-a-service framework (marketed at $380/month on Exploit.IN and Telegram) that compromises WordPress sites to serve ClickFix PowerShell lures, then resolves rotating payload-hosting domains via Polygon smart contract RPC lookups so the C2 infrastructure can be updated without touching the compromised sites. ErrTraffic has been observed delivering Vidar, Okobot, LegionLoader, OnionDrop, BabaDedaLoader, and a gRPC-over-Tor Node.js backdoor. Because outright blocking blockchain traffic is impractical for organizations that rely on legitimate Web3 services, defenders are advised to monitor outbound JSON-RPC/eth_call traffic to public blockchain endpoints as an early-warning signal, apply blockchain analytics to profile wallet-level adversary infrastructure, and restrict execution of code obtained through informal recruiting/interview channels and unvetted npm packages.
MITRE ATT&CK techniques used in TL-2026-2547
Collection
T1005 Data from Local System; T1560 Archive Collected Data
Defense Evasion
T1027 Obfuscated Files or Information
Execution
T1059.006 Python; T1059.007 JavaScript; T1204.002 Malicious File
Command and Control
T1071.001 Web Protocols; T1102.001 Dead Drop Resolver; T1571 Non-Standard Port
Discovery
T1082 System Information Discovery
Initial Access
T1195.002 Compromise Software Supply Chain; T1566.002 Spearphishing Link
Credential Access
T1539 Steal Web Session Cookie; T1555.003 Credentials from Web Browsers
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
Affected products and versions in EtherHiding / Blockchain Dead Drops
- npm (JavaScript ecosystem) — Trojanized packages impersonating Tailwind CSS plugins (NullReceiver / Contagious Interview distribution)
Vulnerable versions: bianira-ui 1.27.0; fluid-type-ui 2.0.8; post-css-transfer; scrollbar-hide-plugin; tailwind-anim; tailwind-animation-founder; tailwindcss-anim
Fixed in: N/A - malicious packages removed from registry, not a software vulnerability - General — Software/blockchain developers and cryptocurrency holders (Windows, macOS, Linux)
Vulnerable versions: Any endpoint executing unvetted code from fake 'job assessment' repositories or compromised npm packages
Remediation for EtherHiding / Blockchain Dead Drops
Immediate actions
- Monitor outbound JSON-RPC calls (eth_call and similar) to public blockchain endpoints (BSC, Ethereum, Polygon, TRON, Aptos RPC providers) as an early-warning signal for EtherHiding-style C2 lookups
- Block or alert on known abused public RPC infrastructure such as bsc-testnet-rpc.publicnode.com when observed from endpoint/proxy logs
- Deploy Chrome Enterprise DownloadRestrictions and URLBlocklist policies to block executable downloads and known malicious/ClickFix-style domains
- Block execution of PowerShell/clipboard-paste commands triggered by unsolicited 'CAPTCHA verification' or 'browser update' prompts (ClickFix pattern)
Workarounds
- Restrict developer workstation network policy to deny direct outbound calls to blockchain RPC endpoints where not operationally required, since wholesale blocking of blockchain traffic is generally impractical for organizations using legitimate Web3 services
Longer-term hardening
- Apply blockchain analytics/wallet-level attribution to correlate disparate campaigns to shared operator infrastructure, since EtherHiding operations remain dependent on a small set of centralized RPC API providers despite blockchain decentralization
- Establish vetting/allowlisting controls for npm and other package-manager installs on developer workstations, given repeated DPRK trojanized-package campaigns (NullReceiver, PolinRider)
- Train developers and recruiting-adjacent staff to treat unsolicited LinkedIn/Discord/Telegram recruiter contact requesting execution of 'take-home assessment' code as a Contagious Interview indicator
- Coordinate with law enforcement and blockchain intelligence platforms (e.g., Chainalysis) for takedown of associated off-chain infrastructure, since on-chain components themselves cannot be seized
Timeline of EtherHiding / Blockchain Dead Drops
- ClearFake fake-browser-update campaign (UNC5142) begins distributing malware from compromised websites.
- ClearFake operators begin storing obfuscated JavaScript payloads in Binance Smart Chain smart contracts after prior server infrastructure was disrupted — the first large-scale documented use of the EtherHiding technique.
- Guardio Labs publicly documents and names the 'EtherHiding' technique.
- APNIC documents the Smargaft botnet using BSC RPC queries to retrieve a rotating C2 IP for DDoS attacks and SOCKS5 proxying.
- Chainalysis observes Iran Ministry of Intelligence-linked actors beginning to write C2 routing data into Bitcoin OP_RETURN fields via a Satoshi-era address.
- DPRK-linked UNC5342 adopts EtherHiding within its Contagious Interview campaign — the first observed state-backed use of blockchain-based malware C2.
- ClearFake stage-1 dispatcher smart contract deployed on BSC testnet.
- ClearFake Windows-targeting ClickFix overlay contract deployed on BSC testnet.
- Google Threat Intelligence Group publishes 'DPRK Adopts EtherHiding,' formally attributing the technique to UNC5342 and detailing the JADESNOW/InvisibleFerret/BeaverTail infection chain.
- Threat actor 'LenAI' begins advertising the ErrTraffic Polygon-based malware-as-a-service dead-drop framework on Exploit.IN and Telegram.
- DPRK-linked wallet begins outbound transaction activity later tied to the NullReceiver C2 resolution technique.
- Trojanized npm packages bianira-ui@1.27.0 and fluid-type-ui@2.0.8, impersonating Tailwind CSS plugins, are published carrying the NullReceiver DPRK C2 technique.
- Security researchers publish analysis of ErrTraffic combining WordPress compromise, ClickFix lures, and Polygon smart contract C2 resolution.
- Chainalysis publishes 'Blockchain Dead Drops and EtherHiding,' reporting a 440% surge in malicious on-chain writes since mid-2025 and nation-state actors driving roughly two-thirds of new activity by Q2 2026.
Sources cited for EtherHiding / Blockchain Dead Drops
- Blockchain Dead Drops and EtherHiding
- DPRK Adopts EtherHiding: Nation-State Malware Hiding on Blockchains
- North Korean Hackers Use EtherHiding to Hide Malware Inside Blockchain Smart Contracts
- North Korean hackers use EtherHiding to hide malware on the blockchain
- Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain
- Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet
- Smargaft harnesses EtherHiding for stealthy C2 hosting
- Binance's Smart Chain Exploited in New 'EtherHiding' Malware Campaign
- ErrTraffic Combines WordPress Hacks, Blockchain C2 and Rotating Malware Domains in One Delivery Network
- NullReceiver Is Harder to Discover but Still Exposes a Reusable Attacker Wallet
- ClearFake Malicious Framework Updates Tactics with Binance Smart Chain Obfuscation
More in malware
- MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana Blockchain for C2
- AI-Powered Polymorphic Malware Queries LLMs at Runtime to Evade Signature Detection: PROMPTFLUX and PROMPTSTEAL/LAMEHUG (APT28)
- KREMLIN Banking Malware Forges Chrome/Edge Secure Preferences Integrity Checks to Force-Install Malicious 'AVSync' Extension
- Iranian State Actors Deploy CHOSEN BRICK Windows Malware to Spy on Dissidents, Activists, and Journalists
- Chosen Brick: Iranian State-Sponsored Windows Surveillance Malware Exposed by US, UK, and Dutch Agencies
Detection coverage for TL-2026-2547
As of 2026-09-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2547 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2547
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.