Description

DPRK-linked threat actors have adopted a technique called HashHiding to make their malware command-and-control (C2) infrastructure more resilient against takedowns. The technique uses Ethereum transactions to conceal the IP address and port of an active C2 server inside a transaction recipient address. Instead of depending solely on conventional domains or fixed IP addresses, infected systems can query the blockchain and retrieve updated C2 information, making infrastructure changes more difficult to disrupt. The mechanism is incorporated into JavaScript-based malware and is designed to inspect Ethereum blockchain activity associated with a designated wallet. The malware extracts selected bytes from a transaction address and converts them into an IPv4 address and network port, which are then used to establish communication with the attacker's server. This approach complements the campaign's existing blockchain-based payload delivery methods, allowing operators to change C2 infrastructure through new blockchain transactions without necessarily updating the malware already deployed on compromised systems. The campaign has been associated with malware such as DEV#POPPER.js and OmniStealer, which can target developer environments, credentials, browser information, cryptocurrency wallets and other sensitive data. Organizations should monitor development systems for suspicious Node.js activity, unauthorized npm packages, unusual blockchain RPC requests and unexpected outbound connections. Security teams should also incorporate blockchain-related indicators into threat hunting and continuously monitor for changes in attacker infrastructure.