Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
The malware campaign attributed to North Korean group XCTDH has introduced a technique dubbed HashHiding that encodes IPv4:port pairs into the first six bytes of the recipient address in ordinary Ethereum transfers. The discovery, documented by Ransom-ISAC on September 25, 2026, updates an architecture already observed in October 2025 and drastically reduces the traceable command-and-control surface. The method complements the previous TxDataHiding system on TRON, Aptos, and BSC: it does not replace it, but runs alongside it as an ultra-low-impact on-chain signaling channel.
- HashHiding embeds IPv4:port into the first six bytes of the
toaddress in ordinary Ethereum transfers, with no smart contracts or calldata - The signal wallet
0x33ff3edaf55a8e03dcbc7cb40d498a49cd499891emitted 2,655 outbound beacons between June 23 and September 21, 2026 - The
_Zmodule, 69,470 obfuscated characters deobfuscated to 8,777 bytes, scans blocks with exponential offsets and installs unconditionally on every infection - The BSC contract address
0x9bc1355344b54dedf3e44296916ed15653844509confirms infrastructure continuity with the October 2025 architecture
From Heavy Payloads to Minimalist Signals: The Command Chain Evolution
The technical transition is measurable in the comparison between the two generations documented by Ransom-ISAC. In October 2025, the campaign employed TxDataHiding: payloads embedded in transactions across multiple blockchains, with extraction requiring parsing of voluminous on-chain data. The DEV#POPPER.js RAT totaled roughly 530 lines.
By September 2026, the file had grown to approximately 2,500 lines, but the structural novelty lies in unification: the RAT, dropper, and HashHiding module converge on a single /init endpoint, where the structure was previously parallel. The _Z module is extracted unconditionally from the RAT and concatenated to every spawned child process. According to Ransom-ISAC, the code reads NtuXTb = ZtoHUM._I?._Z with an anti-double-run flag global._t_h, but no conditional gate limits its execution. The component operates as a detached, hidden background process.
Block scanning follows an exponential progression: offsets 0, 1, 2, 4, 8, up to 4096×256. This allows the malware to quickly locate the latest transaction from the attacker-controlled wallet, decode the C2, and retrieve the bootstrap code. The value transferred in HashHiding transactions is negligible: between 0 and 150 wei, commonly termed "burned value."
Provable Decoding: How 20 Bytes Hide 6 Useful Bytes
An Ethereum address is a 20-byte space (40 hex characters). HashHiding overwrites the first six bytes with the IPv4:port, leaving the remaining 14 bytes random or structured. Decoding is verifiable with deobfuscated code: tx.to.substring(2,10).match(/.{2}/g).map(h => parseInt(h,16)).join('.') produces the IP address.
The address 0xB5D6959401bbb5D69594005000ff8C84e0b715b1 decodes to 181[.]214[.]149[.]148:443. The source emphasizes the address is "fabricated": no one holds the corresponding private key, making the recipient a pure transport function. Ransom-ISAC published a demonstrative recipe on CyberChef to replicate the transformation. OpenSourceMalware documented the underlying technique as "NullReceiver" in August 2026, foreshadowing its operational adoption.
Four C2 rotations were observed during the collection period. Resilience stems from update speed: a single transaction from the signal wallet redirects the entire botnet without modifying code on compromised machines.
"HashHiding takes a fundamentally different approach. Instead of hiding large payloads in transaction data, it encodes an IPv4 address and port, six bytes in total, directly into the to address of plain Ethereum coin transfers. No smart contracts, no calldata, no input data." — Ransom-ISAC (via CyberPress)
Why Traditional Defenses Miss the Target
The technique removes C2 from conventional checkpoints. IP blocklists become obsolete by definition: the address changes with a transaction, while the wallet remains constant. DNS filtering is bypassed because resolution occurs on-chain, not on recursive servers. Web proxies and application firewalls do not intercept native Ethereum transactions.
The operational cost for the attacker is near zero. Gas fees on Ethereum are negligible for 0-wei transfers, and blockchain pseudonymity provides a layer of indirection. Compared to EtherHiding or smart-contract embedding techniques, HashHiding eliminates the complexity of code deployment and verification: the transaction is ordinary, indistinguishable from any other low-value transfer.
The limit for defenders is that the signal exists in a domain outside monitored enterprise infrastructure. The wallet 0x33ff...9891 is public and traceable, but the average SOC is not instrumented to correlate suspicious HTTP connections with on-chain transactions.
What to Do Now
- Monitor on-chain the known wallet
0x33ff3edaf55a8e03dcbc7cb40d498a49cd499891and recipient address patterns with prefixes decodable as IPv4:port - Correlate in the SIEM outbound HTTP connections to IPs decodable from Ethereum transactions originating from internal hosts not authorized to operate with cryptocurrencies
- Analyze Node.js or JavaScript processes that perform block scans with exponential offsets or interact with Ethereum RPC endpoints without a documented business case
- Retrieve and verify the
_Zmodule in DEV#POPPER.js images, recognizing it by the base-91 + CFF deobfuscation pattern and characteristic size (approximately 69,500 obfuscated characters)
The Continuity That Betrays: Same Actor, Redefined Architecture
The BSC contract address 0x9bc1355344b54dedf3e44296916ed15653844509 is identical between October 2025 and September 2026. This constant is the most reliable element of infrastructure continuity in an ecosystem where everything else mutates. The campaign is not a reinvention: it is an optimization.
The shift from TxDataHiding to HashHiding as the primary C2 signaling channel reflects operational maturation. Attackers have recognized that on-chain payload weight is a detection risk: the less data stored on the blockchain, the less surface left for analysts. The minimalist signal is also harder to censor: no platform to report, no contract to disable, just an address emitting ordinary transactions.
What remains outside the documented perimeter. The dossier does not specify the number of victims of the HashHiding component nor their geographic distribution. The exact DPRK attribution mechanism is unclear: geopolitical indicators, infrastructure overlap, or shared TTPs. No effective countermeasures beyond monitoring the known wallet are documented. And it is not independently verifiable that the decoded address actually lacks a corresponding key: the source asserts it, but elliptic-curve cryptography does not allow negative proof without a signing attempt.
The technique is now in the public record. The replicable is the first step toward the defensible.
Information verified against cited sources and current as of publication.
Sources
- https://securelist.com/moviereaper-malware-torrent-odyssey-solana/121344/
- https://cyberpress.org/xctdh-hides-malware-c2-on-blockchain/
- https://ransom-isac.org/blog/xctdh-adopts-hash-hiding/
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.