DPRK-Linked Hackers Adopted Blockchain HashHiding
Cybercriminals have utilized the Ethereum network to maintain more resilient command-and-control infrastructure.
Updated on Sept. 29, 2026 in Cybersecurity

Live Poll
Do you believe the expansion of blockchain technology makes our digital infrastructure less secure?
Hackers linked to the Democratic People's Republic of Korea have integrated a new HashHiding technique into their blockchain-backed command-and-control infrastructure. This method enables infected systems to retrieve server data directly from the Ethereum blockchain.
Why it matters
By embedding server details within transaction recipient fields, the attackers have created a takedown-resistant channel for their malware. This innovation allows malicious infrastructure to persist without relying on traditional domains or smart contracts.
The HashHiding technique functions by embedding active command-and-control IP addresses and ports directly into Ethereum transfer recipient addresses. Infected systems scan the blockchain history to recover connection data without executing smart contracts.
The players
Democratic People's Republic of Korea
The Democratic People's Republic of Korea is a sovereign state frequently associated with state-sponsored cyber espionage and financial crime operations.
The details
The XCTDH campaign leverages the Ethereum blockchain to establish a secondary recovery channel for compromised systems. This shift away from conventional domain names makes the attackers' infrastructure significantly harder to disrupt through standard takedown procedures.
Timeline
The implementation of the HashHiding technique was reported in September 2026.
The Tech Race
The transition toward blockchain-based command infrastructure signals a move away from centralized domain management toward decentralized, ledger-based persistence. This development follows a pattern where threat actors increasingly repurpose legitimate distributed technologies to bypass traditional network defenses.
While the technique targets specific infected systems, it highlights the growing necessity for security teams to monitor unconventional blockchain-based traffic patterns. Developers and network administrators should prioritize advanced traffic analysis to identify connections initiated through non-standard channels.
The takeaway
The adoption of blockchain-based concealment demonstrates the persistent innovation of sophisticated threat actors seeking to evade detection. Organizations should adopt a defense-in-depth strategy that accounts for the potential exploitation of distributed ledger technologies in command-and-control operations.
Further reading
For broader trends regarding evolving digital threats, explore our Cybersecurity section.
Live Poll
Do you believe the expansion of blockchain technology makes our digital infrastructure less secure?







