North Korea's NullReceiver C2 Technique Enhances Stealth in Cyber Attacks

North Korea's NullReceiver C2 Technique Enhances Stealth in Cyber Attacks

First seen 6 Aug 2026, 23:23 UTC GbhackersScworld 71% similarity 72.5

Article Content

Browse articles
ThreatCluster

North Korean threat actors have introduced a new command-and-control (C2) technique named NullReceiver, which conceals the C2 server's IP address within empty Ethereum transactions. This method, an evolution of EtherHiding, was found in two trojanized npm packages, bianira-ui and fluid-type-ui, which mimic Tailwind CSS plugins. The technique allows malware to decode the IP address from the recipient address of a zero-value Ethereum transfer, making detection and attribution more difficult. While the packages have been downloaded a few hundred times, the method's stealthiness and reduced cost make it a significant advancement in C2 strategies. NullReceiver limits the data encoded to just a few bytes, enhancing its resilience against detection. The attack primarily affects users of the compromised npm packages, raising concerns over supply chain security.

Key Points: • NullReceiver is a new C2 technique from North Korea that hides IP addresses in Ethereum transactions. • Two trojanized npm packages, bianira-ui and fluid-type-ui, implement this stealthy method. • The technique improves upon EtherHiding by eliminating fixed destination addresses, complicating attribution.

ThreatCluster AI How this analysis works

Timeline

2026-08-04
NullReceiver technique reported
Gbhackers reported on the new NullReceiver C2 technique used by North Korean actors, highlighting its stealth features.
Gbhackers
2026-08-06
NullReceiver linked to North Korea
Scworld confirmed that North Korean threat actors are behind the NullReceiver technique, enhancing their C2 capabilities.
Scworld

Community

Browse all →