North Korea's Hackers Evade Detection with New Blockchain-Based C2 Tactic
Cybersecurity researchers have discovered a new tactic employed by North Korean hacking groups to conceal command-and-control (C2) server IP addresses, dubbed 'NullReceiver.'
This approach is an evolution of the 'EtherHiding' technique, which involves embedding nefarious code within a smart contract on a public blockchain. NullReceiver decodes the C2 IP address from the bytes of the recipient address of a zero-value Ethereum transfer.
The tactic has been observed in two trojanized npm packages, 'bianira-ui' and 'fluid-type-ui', which have been downloaded 109 and 587 times respectively since their publication on July 28, 2026. The packages are no longer available for download from npm.