Skip to content
North Korea's NullReceiver C2 Technique Enhances Stealth in Cyber Attacks

North Korea's NullReceiver C2 Technique Enhances Stealth in Cyber Attacks

First seen 6 Aug 2026, 23:23 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster August 7, 2026 at 23:08 UTC
  • NullReceiver is a new C2 technique from North Korea that hides IP addresses in Ethereum transactions.
  • Two trojanized npm packages, bianira-ui and fluid-type-ui, implement this stealthy method.
  • The technique improves upon EtherHiding by eliminating fixed destination addresses, complicating attribution.

North Korean threat actors have introduced a new command-and-control (C2) technique named NullReceiver, which conceals the C2 server's IP address within empty Ethereum transactions. This method, an evolution of EtherHiding, was found in two trojanized npm packages, bianira-ui and fluid-type-ui, which mimic Tailwind CSS plugins. The technique allows malware to decode the IP address from the recipient address of a zero-value Ethereum transfer, making detection and attribution more difficult. While the packages have been downloaded a few hundred times, the method's stealthiness and reduced cost make it a significant advancement in C2 strategies. NullReceiver limits the data encoded to just a few bytes, enhancing its resilience against detection. The attack primarily affects users of the compromised npm packages, raising concerns over supply chain security.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 45d ago How this analysis works

Timeline

2026-08-04
NullReceiver technique reported
Gbhackers reported on the new NullReceiver C2 technique used by North Korean actors, highlighting its stealth features.
Gbhackers
2026-08-06
NullReceiver linked to North Korea
Scworld confirmed that North Korean threat actors are behind the NullReceiver technique, enhancing their C2 capabilities.
Scworld

More articles in this cluster (3)

Following this threat?

Track NullReceiver and Ethereum in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed