NullReceiver's Blank Crypto Transfers Solves the Challenges of EtherHiding

2026-08-02 Open Source Malware

https://opensourcemalware.com/blog/nullreceiver-dprk-c2-technique

Thumbnail for NullReceiver's Blank Crypto Transfers Solves the Challenges of EtherHiding

DPRK-linked Contagious Interview operators embedded NullReceiver in the trojanized npm packages bianira-ui and fluid-type-ui. The technique retrieves an attacker's latest zero-value, zero-data Ethereum transaction and decodes a C2 IP address from the recipient address itself. Unlike EtherHiding, it requires no smart contract, fixed burn address, or calldata, reducing the transaction features defenders can fingerprint. Static analysis identified the wallet used for blockchain lookups and decoded the active C2 address as 166.88.134.62.

Indicators of Compromise

Type Value First Seen Last Seen
WALLET 0xa658863ea658863e68656c6c6f697… 2026-08-02 2026-08-02
WALLET 0xa322e5f3d311d3080e6f0121063e9… 2026-08-02 2026-08-02
IPv4 166.88.134.62 2026-07-28 2026-08-02

Related Actors

Related Reports

« Back