XCTDH Adopts Hash Hiding

2026-09-25 • Ransom ISAC •

https://ransom-isac.org/blog/xctdh-adopts-hash-hiding

Thumbnail for XCTDH Adopts Hash Hiding

The DPRK-attributed XCTDH campaign added HashHiding, also known as NullReceiver, as an always-on Ethereum channel for recovering its current command-and-control address. Malware decodes an IPv4 address and port from fabricated Ethereum transaction destinations sent by a signal wallet that produced 2,655 beacons over roughly 90 days. The channel operates alongside hardcoded infrastructure and the campaign's existing TRON/Aptos-to-BSC chain, supporting DEV#POPPER.js and the OmniStealer credential harvester. Ransom-ISAC observed four encoded destinations and three C2 IP addresses during the collection period.

Indicators of Compromise

Type Value First Seen Last Seen
YARA XCTDH_HashHiding_NullReceiver 2026-09-25 2026-09-25
WALLET 0xB5D6959401bbb5D69594005000ff8… 2026-09-25 2026-09-25
WALLET 0xB5D6959301bbB5D69593005000FfA… 2026-09-25 2026-09-25
WALLET 0x171B14bb01bB171B14BB0050EB7f3… 2026-09-25 2026-09-25
WALLET 0x171B14bB0050171b14Bb01BB398EA… 2026-09-25 2026-09-25
WALLET 0x33ff3edaf55a8e03dcbc7cb40d498… 2026-09-25 2026-09-25
URL http://181.214.149.148:443/boot 2026-09-25 2026-09-25
IPv4 181.214.149.148 2026-09-25 2026-09-25
IPv4 181.214.149.147 2026-09-25 2026-09-25
IPv4 23.27.20.187 2026-09-25 2026-09-25
WALLET 0x9bc1355344b54dedf3e44296916ed… 2026-07-28 2026-09-25

Related Reports

« Back