Scworld
North Korea's NullReceiver C2 Technique Enhances Stealth in Cyber Attacks
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
North Korean threat actors have introduced a new command-and-control (C2) technique named NullReceiver, which conceals the C2 server's IP address within empty Ethereum transactions. This method, an evolution of EtherHiding, was found in two trojanized npm packages, bianira-ui and fluid-type-ui, which mimic Tailwind CSS plugins. The technique allows malware to decode the IP address from the recipient address of a zero-value Ethereum transfer, making detection and attribution more difficult. While the packages have been downloaded a few hundred times, the method's stealthiness and reduced cost make it a significant advancement in C2 strategies. NullReceiver limits the data encoded to just a few bytes, enhancing its resilience against detection. The attack primarily affects users of the compromised npm packages, raising concerns over supply chain security.
Key Points: • NullReceiver is a new C2 technique from North Korea that hides IP addresses in Ethereum transactions. • Two trojanized npm packages, bianira-ui and fluid-type-ui, implement this stealthy method. • The technique improves upon EtherHiding by eliminating fixed destination addresses, complicating attribution.