A sophisticated malware campaign linked to North Korea has been uncovered, utilizing Ethereum transactions to discreetly maintain communication with infected computers. Unlike traditional methods, this operation embeds the location of a control server within Ethereum transfers rather than storing the malware directly on the blockchain. The campaign targets developers through deceptive job offers, compromised code repositories, and harmful software packages. When these malicious codes are executed, they can install a remote access tool and a credential stealer on devices running Windows, macOS, or Linux.
Ransom-ISAC researchers identified this new Ethereum component in September 2026, analyzing samples of the malware XCTDH. Their findings, shared in a report, reveal that this technique provides an alternative communication channel for the malware, ensuring it remains connected even if other pathways are disrupted. Although the campaign was first documented in October 2025, the Ethereum signaling began in June 2026, involving 2,655 transactions over a 90-day period. The report, however, does not specify the number of infected computers or the extent of data theft.
The method, referred to as HashHiding, uses the recipient address of an Ethereum transfer to encode a message. This message includes the internet address and port of the control server. Unlike placing entire malware payloads in blockchain data, these transactions do not contain smart contract calls or hidden scripts. Most transfers involve no actual cryptocurrency, with a few exceptions transferring negligible amounts to addresses with inaccessible private keys.
The malware monitors transactions sent from an operator's signaling wallet, scanning recent Ethereum blocks via public access points, identifying matching transfers, and decoding the recipient address to contact the server. This server then supplies code to rebuild the infection. The campaign distinguishes itself from related methods like NullReceiver, as the blockchain address here serves as a signpost rather than a storage site.
Throughout the observation period, the operator altered the encoded destination multiple times to evade detection. Initially, signals pointed to the same internet address with different ports, later shifting to new address ranges. One change involved altering only the final number of the server address, potentially bypassing blocklists. Besides Ethereum, the operation also uses TRON and Aptos as initial loaders, while BNB Smart Chain transactions store encrypted JavaScript.
The attack typically begins when a developer falls for a fake recruitment prompt, executing a contaminated project or package. These JavaScript loaders can access blockchain services post-execution, facilitating further stages without apparent malicious links. The remote access tool can execute commands, log keystrokes, and monitor the clipboard. A separate credential stealer targets browser information and cryptocurrency wallets, with stolen data being exfiltrated through a messaging bot interface.
Unlike previous attacks, the Ethereum scanner operates alongside the remote access tool, not just when a connection fails. Hardcoded server locations and cross-chain paths remain active, meaning blocking a server or blockchain access point may not suffice. This campaign poses a significant risk similar to developer attacks leveraging blockchain payloads, where a seemingly legitimate development task triggers a compromise.

