North Korean APT XCTDH uses Ethereum for command infrastructure

On September 29, 2026, cybersecurity researchers reported that the North Korean APT group XCTDH has adopted a technique called HashHiding to hide command-and-control infrastructure by encoding IPv4:port pairs within Ethereum blockchain transaction recipient addresses.

2 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

North Korean APT XCTDH now hides C2 infrastructure in Ethereum transaction addresses using a technique called HashHiding. IPv4:port pairs encoded in recipient addresses drastically https:// deafnews.i

mastodon:infosec-exchangeother5h ago kagi ↗

North Korean APT XCTDH now hides C2 infrastructure in Ethereum transaction addresses using a technique called HashHiding. IPv4:port pairs encoded in recipient addresses drastically https:// deafnews.it/en/article/xctdh-a dopts-hashhiding-c2-now-travels-over-ethereum-addresses

XCTDH Adopts HashHiding: C2 Now Travels Over Ethereum Addresses

stream:bsky-jetstreamother5h ago kagi ↗

XCTDH Adopts HashHiding: C2 Now Travels Over Ethereum Addresses The malware campaign attributed to North Korean group XCTDH has introduced a technique dubbed HashHiding that encodes IPv4:port pairs into the first six bytes of ordinary Ethereum transaction recipient addresses. Documented by Ransom-ISAC on September 25, 2026, the method updates an architecture fir