DPRK-linked threat actors have adopted a technique called HashHiding to make their malware command-and-control (C2) infrastructure more resilient against takedowns. The technique uses Ethereum transactions to conceal the IP address and port of an active C2 server inside a transaction recipient address. Instead of depending solely on conventional domains or fixed IP addresses, infected systems can query the blockchain and retrieve updated C2 information, making infrastructure changes more difficult to disrupt. The mechanism is incorporated into JavaScript-based malware and is designed to inspect Ethereum blockchain activity associated with a designated wallet. The malware extracts selected bytes from a transaction address and converts them into an IPv4 address and network port, which are then used to establish communication with the attacker's server. This approach complements the campaign's existing blockchain-based payload delivery methods, allowing operators to change C2 infrastructure through new blockchain transactions without necessarily updating the malware already deployed on compromised systems. The campaign has been associated with malware such as DEV#POPPER.js and OmniStealer, which can target developer environments, credentials, browser information, cryptocurrency wallets and other sensitive data. Organizations should monitor development systems for suspicious Node.js activity, unauthorized npm packages, unusual blockchain RPC requests and unexpected outbound connections. Security teams should also incorporate blockchain-related indicators into threat hunting and continuously monitor for changes in attacker infrastructure.
A newly demonstrated security flaw in LibreOffice and Apache OpenOffice shows how seemingly legitimate spreadsheet features can be combined to execute malicious code without the us...
Four vulnerabilities disclosed in Apache Struts could expose affected applications to remote code execution, denial of service, resource exhaustion, and cross-user data disclosure....
Atlassian has disclosed a critical arbitrary file access vulnerability, CVE-2026-21589, affecting Jira Software Data Center and Confluence Data Center. Rated CVSS 9.3, the flaw all...