North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling

North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum (TL-2026-2782), also tracked as XCTDH, is a high-severity malware campaign, first published 2026-09-29. It is attributed to Contagious Interview (North Korea) with medium confidence, affects Various Developer workstations (Windows, macOS, Linux) running, maps to 15 MITRE ATT&CK techniques (T1027, T1056.001, T1059.006), and is covered by 9 detection rules and 23 indicators of compromise.

Key facts for TL-2026-2782

Threat ID
TL-2026-2782
Also known as
XCTDH, Cross-Chain TxDataHiding, HashHiding, NullReceiver-style dead drop
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-09-29
Last reviewed
2026-09-29
Attribution
Contagious Interview
Attribution confidence
MEDIUM
Nation-state nexus
North Korea
Motivation
FINANCIAL
Target sectors
technology, software-development, cryptocurrency, finance
Target regions
Global
Detection rules
9
Indicators of compromise
23

Malware and tooling in North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum

Malware and tooling: DEV#POPPER.js, OmniStealer, Python, _Z, telegram

DPRK-linked operators behind the Cross-Chain TxDataHiding (XCTDH) campaign encode the active C2 IPv4 address and port in the recipient address of ordinary Ethereum transfers ("HashHiding"), alongside TRON, Aptos and BNB Smart Chain layers that deliver encrypted JavaScript payloads. The DEV#POPPER.js Node.js RAT and the Python OmniStealer credential stealer are delivered to developers through fake job offers, trojanized GitHub repositories and npm packages on Windows, macOS and Linux.

How North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum works

Ransom-ISAC ("XCTDH Adopts Hash Hiding", September 2026) documents a DPRK-linked campaign first described in October 2025 as Cross-Chain TxDataHiding (XCTDH). The operators added an Ethereum-based recovery channel called HashHiding. Instead of storing payloads in smart contracts or transaction calldata (EtherHiding / TxDataHiding), the attacker's signal wallet 0x33ff3edaf55a8e03dcbc7cb40d498a49cd499891 sends mostly zero-value transfers whose recipient (`to`) address carries six bytes of data: the first 4 bytes are an IPv4 address and the next 2 bytes the port; further bytes carry a second IP/port pair (80) and padding. Ransom-ISAC observed 2,655 such beacon transactions between 2026-06-23 15:21 UTC and 2026-09-21 21:25 UTC (about one every 49-51 minutes, mostly 0 wei, some 150 wei) and four C2 rotations: 23.27.20.187:80, 23.27.20.187:443, 181.214.149.147:443 and 181.214.149.148:443. Most transfers move no cryptocurrency; a few send a tiny amount to an address whose private key nobody is expected to control. The technique closely resembles the "NullReceiver" dead-drop resolver that OpenSourceMalware disclosed in August 2026 in trojanized npm packages (bianira-ui, fluid-type-ui), which was also linked to the DPRK Contagious Interview activity.

Delivery targets developers. Victims receive fake job offers (Telegram-based), then run a trojanized GitHub repository or npm package, or a poisoned configuration file (e.g. config.js, tailwind.config.js) in which obfuscated JavaScript is appended after whitespace padding. The loader queries TRON wallets for the latest transaction, decodes a reversed BNB Smart Chain (BSC) transaction hash from it, and fetches an XOR-encrypted payload from BSC calldata; Aptos serves as a fallback pointer. Three channels run unconditionally in parallel: a hardcoded C2 IP (181.214.149.148:443 in the September chain), the TRON/Aptos-to-BSC XCTDH chain, and HashHiding on Ethereum. The C2 /init endpoint (443) returns a ~303KB JSON blob with `_B` (the DEV#POPPER.js RAT) and `_Z` (the HashHiding scanner, 69,470 characters obfuscated with base-91 using 18 custom alphabets plus generator-based control-flow flattening). `_Z` scans Ethereum mainnet at exponentially growing block offsets through public RPC providers (publicnode.com, drpc.org, blastapi.io), looks for transfers from the signal wallet, decodes the recipient address, fetches /boot (443) to load boot.js, then re-fetches /init and evals the RAT. A parallel path via /$/boot (80, XOR-encrypted dropper that installs Python 3.13 and 7-Zip) and /$/1 (80, OmniStealer) delivers the stealer.

DEV#POPPER.js is a cross-platform Node.js RAT (grown from ~530 lines in October 2025 to ~2,500 in September 2026) with WebSocket C2, shell command execution, keylogging and clipboard monitoring, and it persists by injecting into VSCode/Cursor and spawning the `_Z` module in every child process. OmniStealer is a ~3,500-line Python stealer targeting 153 cryptocurrency wallet targets plus browsers, password managers and cloud-storage credentials on Windows, macOS and Linux; it runs once (fire-and-forget), packs loot into an AES-encrypted ZIP and exfiltrates via the Telegram bot API. Campaign markers: `global.i = '5-3-132'`, `/*RS260605*/` (`_Z` version), OmniStealer build `B9=260924`, Node.js requests spoofing `Python-urllib/3.13`, and a custom `Sec-V` header. Attribution to North Korea rests on overlap with the Contagious Interview / Famous Chollima activity and on infrastructure continuity (the same BSC address and XOR key as the October 2025 chain); the report does not establish a victim count. Google GTIG's earlier reporting on UNC5342 (October 2025) describes related DPRK use of EtherHiding on BSC, and lists 0x9bc1355344b54dedf3e44296916ed15653844509 as the owner address of its BSC contract, which is the same address Ransom-ISAC lists as the BSC payload sender here.

MITRE ATT&CK techniques used in TL-2026-2782

Defense Evasion

T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information

Collection

T1056.001 Keylogging; T1560.001 Archive via Utility

Execution

T1059.006 Python; T1059.007 JavaScript; T1204.002 Malicious File

Command and Control

T1071.001 Web Protocols; T1102.001 Dead Drop Resolver; T1219 Remote Access Tools

Initial Access

T1195.001 Compromise Software Dependencies and Development Tools; T1566.003 Spearphishing via Service

Credential Access

T1555.003 Credentials from Web Browsers; T1555.005 Password Managers

Exfiltration

T1567 Exfiltration Over Web Service

Affected products and versions in North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum

  • Various — Developer workstations (Windows, macOS, Linux) running Node.js/npm and Python
    Vulnerable versions: Systems that execute trojanized GitHub repositories, npm packages or poisoned config files
  • Microsoft / Anysphere — VSCode / Cursor IDE (targeted for persistence by DEV#POPPER.js)
    Vulnerable versions: Not version-specific

Remediation for North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum

Immediate actions

  • Block egress to 23.27.20.143, 23.27.20.187, 181.214.149.147 and 181.214.149.148 (ports 80/443/27017)
  • Hunt developer endpoints for Node.js processes started with -eval containing global.i= / global.r=require and for the strings '5-3-132', '/*RS260605*/' and 'B9=260924'
  • Alert on Node.js processes issuing JSON-RPC calls (eth_getBlockByNumber, eth_getTransactionByHash, eth_call) to Ethereum, TRON, Aptos or BSC RPC endpoints
  • If a host ran an untrusted repo or npm package from a job assessment, treat it as compromised: rotate browser, password-manager, cloud and wallet credentials and move crypto assets from a clean device

Workarounds

  • Inspect config files (config.js, tailwind.config.js) for long whitespace padding followed by appended JavaScript before running a repo
  • Review npm dependencies for the packages bianira-ui and fluid-type-ui

Longer-term hardening

  • Restrict direct access to public blockchain RPC endpoints from developer workstations and build systems, or route them through a proxy with logging
  • Run code from job assessments and unknown repositories only in disposable sandboxes or VMs
  • Audit VSCode/Cursor extension and settings changes on developer machines
  • Because removing a known C2 IP is not enough when malware reads new addresses from public blockchain records, monitor the signal wallet and BSC address for new transactions

Timeline of North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum

  • Google GTIG later reports that DPRK cluster UNC5342 began using EtherHiding on public blockchains around February 2025 (related Contagious Interview activity).
  • Ransom-ISAC first documents the Cross-Chain TxDataHiding (XCTDH) campaign, with a C2 at 23.27.20.143:27017 and a ~530-line DEV#POPPER.js RAT (exact day not stated; month per report).
  • Google GTIG publishes 'DPRK Adopts EtherHiding' describing UNC5342 use of BSC/Ethereum smart contracts, JADESNOW, BEAVERTAIL and INVISIBLEFERRET.
  • First HashHiding beacon from signal wallet 0x33ff3eda...9891 at 15:21 UTC, encoding 23.27.20.187:80.
  • Encoded destination changes to 23.27.20.187:443 (0x171B14bb01bB171B14BB0050EB7f39C35C47E682); it remains active until September 3.
  • Trojanized npm packages bianira-ui and fluid-type-ui, later tied by OpenSourceMalware to DPRK Contagious Interview and named NullReceiver, are first published.
  • OpenSourceMalware publicly discloses the NullReceiver technique (August 2026; exact day approximate), which encodes a C2 IP in the recipient address of an empty Ethereum transfer.
  • Encoded destination changes to 181.214.149.147:443 (0xB5D6959301bbB5D69593005000FfABa8a5A2ADA2).
  • Encoded destination changes to 181.214.149.148:443 (0xB5D6959401bbb5D69594005000ff8C84e0b715b1), the last of four observed C2 rotations.
  • End of Ransom-ISAC's 90-day collection window; last beacon at 21:25 UTC, 2,655 transactions in total.
  • OmniStealer build marker B9=260924 (September 24, 2026) seen in the delivered stealer.
  • Cyber Security News, GBHackers and Cyberpress publicize Ransom-ISAC's 'XCTDH Adopts Hash Hiding' findings.

Sources cited for North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum

More in malware

Detection coverage for TL-2026-2782

As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2782 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-2782

2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats