NullReceiver Hides C2 in Blank Ethereum Transfers, North Korean Threat Actors Found Using New Technique
Cyber threat actors linked to North Korea have been using a new technique called NullReceiver to hide command-and-control (C2) IP addresses within Ethereum transfers. This method embeds the C2 IP address in the recipient address bytes of zero-value Ethereum transactions, making it more difficult to detect than traditional EtherHiding methods.
The malicious activity was discovered through an investigation into npm packages, which revealed two trojanized packages, bianira-ui and fluid-type-ui, using NullReceiver to resolve C2 infrastructure. The researchers used static analysis of published npm tarballs and read-only examination of attacker-controlled transactions on the public blockchain to identify the malicious activity.
Defenders should be aware of this new technique and monitor blockchain activity associated with known attacker-controlled Ethereum wallets. They should also inspect recipient addresses used in zero-value transfers for potential C2 IP addresses.