NK Threat Actors Hide C2 in Blank Ethereum Transfers
Threat actors linked to North Korea have developed a new method of establishing command-and-control (C2) infrastructure using the Ethereum blockchain. The technique, known as NullReceiver, embeds C2 IP addresses within the recipient address bytes of zero-value Ethereum transfers.
This makes detection more difficult than traditional methods, such as EtherHiding, which involve hiding malware in plain text on the blockchain.
Researchers have identified two malicious npm packages, bianira-ui and fluid-type-ui, that use NullReceiver to resolve C2 infrastructure. These packages are distributed through trojanized npm packages.
To mitigate this threat, defenders should monitor blockchain activity associated with known attacker-controlled Ethereum wallets and inspect recipient addresses used in zero-value transfers.