North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling
North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum (TL-2026-2782), also tracked as XCTDH, is a high-severity malware campaign, first published 2026-09-29. It is attributed to Contagious Interview (North Korea) with medium confidence, affects Various Developer workstations (Windows, macOS, Linux) running, maps to 15 MITRE ATT&CK techniques (T1027, T1056.001, T1059.006), and is covered by 9 detection rules and 23 indicators of compromise.
Key facts for TL-2026-2782
- Threat ID
- TL-2026-2782
- Also known as
- XCTDH, Cross-Chain TxDataHiding, HashHiding, NullReceiver-style dead drop
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-09-29
- Last reviewed
- 2026-09-29
- Attribution
- Contagious Interview
- Attribution confidence
- MEDIUM
- Nation-state nexus
- North Korea
- Motivation
- FINANCIAL
- Target sectors
- technology, software-development, cryptocurrency, finance
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 23
Malware and tooling in North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum
Malware and tooling: DEV#POPPER.js, OmniStealer, Python, _Z, telegram
DPRK-linked operators behind the Cross-Chain TxDataHiding (XCTDH) campaign encode the active C2 IPv4 address and port in the recipient address of ordinary Ethereum transfers ("HashHiding"), alongside TRON, Aptos and BNB Smart Chain layers that deliver encrypted JavaScript payloads. The DEV#POPPER.js Node.js RAT and the Python OmniStealer credential stealer are delivered to developers through fake job offers, trojanized GitHub repositories and npm packages on Windows, macOS and Linux.
How North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum works
Ransom-ISAC ("XCTDH Adopts Hash Hiding", September 2026) documents a DPRK-linked campaign first described in October 2025 as Cross-Chain TxDataHiding (XCTDH). The operators added an Ethereum-based recovery channel called HashHiding. Instead of storing payloads in smart contracts or transaction calldata (EtherHiding / TxDataHiding), the attacker's signal wallet 0x33ff3edaf55a8e03dcbc7cb40d498a49cd499891 sends mostly zero-value transfers whose recipient (`to`) address carries six bytes of data: the first 4 bytes are an IPv4 address and the next 2 bytes the port; further bytes carry a second IP/port pair (80) and padding. Ransom-ISAC observed 2,655 such beacon transactions between 2026-06-23 15:21 UTC and 2026-09-21 21:25 UTC (about one every 49-51 minutes, mostly 0 wei, some 150 wei) and four C2 rotations: 23.27.20.187:80, 23.27.20.187:443, 181.214.149.147:443 and 181.214.149.148:443. Most transfers move no cryptocurrency; a few send a tiny amount to an address whose private key nobody is expected to control. The technique closely resembles the "NullReceiver" dead-drop resolver that OpenSourceMalware disclosed in August 2026 in trojanized npm packages (bianira-ui, fluid-type-ui), which was also linked to the DPRK Contagious Interview activity.
Delivery targets developers. Victims receive fake job offers (Telegram-based), then run a trojanized GitHub repository or npm package, or a poisoned configuration file (e.g. config.js, tailwind.config.js) in which obfuscated JavaScript is appended after whitespace padding. The loader queries TRON wallets for the latest transaction, decodes a reversed BNB Smart Chain (BSC) transaction hash from it, and fetches an XOR-encrypted payload from BSC calldata; Aptos serves as a fallback pointer. Three channels run unconditionally in parallel: a hardcoded C2 IP (181.214.149.148:443 in the September chain), the TRON/Aptos-to-BSC XCTDH chain, and HashHiding on Ethereum. The C2 /init endpoint (443) returns a ~303KB JSON blob with `_B` (the DEV#POPPER.js RAT) and `_Z` (the HashHiding scanner, 69,470 characters obfuscated with base-91 using 18 custom alphabets plus generator-based control-flow flattening). `_Z` scans Ethereum mainnet at exponentially growing block offsets through public RPC providers (publicnode.com, drpc.org, blastapi.io), looks for transfers from the signal wallet, decodes the recipient address, fetches /boot (443) to load boot.js, then re-fetches /init and evals the RAT. A parallel path via /$/boot (80, XOR-encrypted dropper that installs Python 3.13 and 7-Zip) and /$/1 (80, OmniStealer) delivers the stealer.
DEV#POPPER.js is a cross-platform Node.js RAT (grown from ~530 lines in October 2025 to ~2,500 in September 2026) with WebSocket C2, shell command execution, keylogging and clipboard monitoring, and it persists by injecting into VSCode/Cursor and spawning the `_Z` module in every child process. OmniStealer is a ~3,500-line Python stealer targeting 153 cryptocurrency wallet targets plus browsers, password managers and cloud-storage credentials on Windows, macOS and Linux; it runs once (fire-and-forget), packs loot into an AES-encrypted ZIP and exfiltrates via the Telegram bot API. Campaign markers: `global.i = '5-3-132'`, `/*RS260605*/` (`_Z` version), OmniStealer build `B9=260924`, Node.js requests spoofing `Python-urllib/3.13`, and a custom `Sec-V` header. Attribution to North Korea rests on overlap with the Contagious Interview / Famous Chollima activity and on infrastructure continuity (the same BSC address and XOR key as the October 2025 chain); the report does not establish a victim count. Google GTIG's earlier reporting on UNC5342 (October 2025) describes related DPRK use of EtherHiding on BSC, and lists 0x9bc1355344b54dedf3e44296916ed15653844509 as the owner address of its BSC contract, which is the same address Ransom-ISAC lists as the BSC payload sender here.
MITRE ATT&CK techniques used in TL-2026-2782
Defense Evasion
T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information
Collection
T1056.001 Keylogging; T1560.001 Archive via Utility
Execution
T1059.006 Python; T1059.007 JavaScript; T1204.002 Malicious File
Command and Control
T1071.001 Web Protocols; T1102.001 Dead Drop Resolver; T1219 Remote Access Tools
Initial Access
T1195.001 Compromise Software Dependencies and Development Tools; T1566.003 Spearphishing via Service
Credential Access
T1555.003 Credentials from Web Browsers; T1555.005 Password Managers
Exfiltration
Affected products and versions in North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum
- Various — Developer workstations (Windows, macOS, Linux) running Node.js/npm and Python
Vulnerable versions: Systems that execute trojanized GitHub repositories, npm packages or poisoned config files - Microsoft / Anysphere — VSCode / Cursor IDE (targeted for persistence by DEV#POPPER.js)
Vulnerable versions: Not version-specific
Remediation for North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum
Immediate actions
- Block egress to 23.27.20.143, 23.27.20.187, 181.214.149.147 and 181.214.149.148 (ports 80/443/27017)
- Hunt developer endpoints for Node.js processes started with -eval containing global.i= / global.r=require and for the strings '5-3-132', '/*RS260605*/' and 'B9=260924'
- Alert on Node.js processes issuing JSON-RPC calls (eth_getBlockByNumber, eth_getTransactionByHash, eth_call) to Ethereum, TRON, Aptos or BSC RPC endpoints
- If a host ran an untrusted repo or npm package from a job assessment, treat it as compromised: rotate browser, password-manager, cloud and wallet credentials and move crypto assets from a clean device
Workarounds
- Inspect config files (config.js, tailwind.config.js) for long whitespace padding followed by appended JavaScript before running a repo
- Review npm dependencies for the packages bianira-ui and fluid-type-ui
Longer-term hardening
- Restrict direct access to public blockchain RPC endpoints from developer workstations and build systems, or route them through a proxy with logging
- Run code from job assessments and unknown repositories only in disposable sandboxes or VMs
- Audit VSCode/Cursor extension and settings changes on developer machines
- Because removing a known C2 IP is not enough when malware reads new addresses from public blockchain records, monitor the signal wallet and BSC address for new transactions
Timeline of North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum
- Google GTIG later reports that DPRK cluster UNC5342 began using EtherHiding on public blockchains around February 2025 (related Contagious Interview activity).
- Ransom-ISAC first documents the Cross-Chain TxDataHiding (XCTDH) campaign, with a C2 at 23.27.20.143:27017 and a ~530-line DEV#POPPER.js RAT (exact day not stated; month per report).
- Google GTIG publishes 'DPRK Adopts EtherHiding' describing UNC5342 use of BSC/Ethereum smart contracts, JADESNOW, BEAVERTAIL and INVISIBLEFERRET.
- First HashHiding beacon from signal wallet 0x33ff3eda...9891 at 15:21 UTC, encoding 23.27.20.187:80.
- Encoded destination changes to 23.27.20.187:443 (0x171B14bb01bB171B14BB0050EB7f39C35C47E682); it remains active until September 3.
- Trojanized npm packages bianira-ui and fluid-type-ui, later tied by OpenSourceMalware to DPRK Contagious Interview and named NullReceiver, are first published.
- OpenSourceMalware publicly discloses the NullReceiver technique (August 2026; exact day approximate), which encodes a C2 IP in the recipient address of an empty Ethereum transfer.
- Encoded destination changes to 181.214.149.147:443 (0xB5D6959301bbB5D69593005000FfABa8a5A2ADA2).
- Encoded destination changes to 181.214.149.148:443 (0xB5D6959401bbb5D69594005000ff8C84e0b715b1), the last of four observed C2 rotations.
- End of Ransom-ISAC's 90-day collection window; last beacon at 21:25 UTC, 2,655 transactions in total.
- OmniStealer build marker B9=260924 (September 24, 2026) seen in the delivered stealer.
- Cyber Security News, GBHackers and Cyberpress publicize Ransom-ISAC's 'XCTDH Adopts Hash Hiding' findings.
Sources cited for North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum
- Hackers Turned Ethereum Into a Secret Messaging System for Malware
- XCTDH Adopts Hash Hiding (Ransom-ISAC)
- DPRK-Linked Hackers Add HashHiding to Blockchain C2 Network for Takedown-Resistant Malware
- XCTDH Campaign Uses HashHiding and Blockchain Transactions to Hide Malware C2 Infrastructure
- DPRK Adopts EtherHiding: Nation-State Threat Actors Increasingly Leveraging Blockchain (Google GTIG)
- North Korean hackers use EtherHiding to hide malware on the blockchain (BleepingComputer)
- Trojanized npm packages decode C2 IP from Ethereum transfers (The Hacker News)
- Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads (Sonatype)
- XCTDH research presented at BSidesLuxembourg 2026
More in malware
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows Defenses
- OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installers
- Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of Canon and Stardock Binaries
- Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against Korean companies
- Infostealer-Stolen AI Service Logins Expose 80,000+ Corporate Domains (Shadow AI to LLMjacking)
Detection coverage for TL-2026-2782
As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2782 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2782
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.