Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Ethereum Used for Covert Malware Communication

Ethereum Used for Covert Malware Communication

Posted on September 29, 2026 By CWS

Hackers Exploit Ethereum for Stealthy Malware Communication

A recent cybersecurity revelation has spotlighted how malicious actors linked to North Korea have ingeniously utilized Ethereum blockchain transactions to maintain communication with compromised systems. This method cleverly disguises the whereabouts of their control servers within cryptocurrency transfers, allowing them to evade detection and continue their operations uninterrupted.

The campaign primarily targets software developers through deceptive job offers, contaminated code libraries, and harmful software packages. Execution of such malicious code results in the installation of tools for remote access and credential theft across various operating systems, including Windows, macOS, and Linux.

Methodology: Using Ethereum Transactions

In a report shared with Cyber Security News, researchers at Ransom-ISAC uncovered this novel malware tactic in September 2026. The technique serves as a fallback communication channel for the malware, ensuring uninterrupted connectivity to its operators even if conventional routes are blocked.

First documented in October 2025, the campaign’s Ethereum-based signals began surfacing in June 2026, with researchers recording 2,655 transactions over a 90-day span. The exact number of affected systems or the volume of stolen data remains unknown.

HashHiding: A Covert Messaging System

Ransom-ISAC identified the technique as HashHiding, where an Ethereum transfer’s recipient address is encoded with the server’s internet address and port. Unlike placing malware payloads directly in blockchain transactions, this method uses minimal data to communicate key server locations.

These transactions typically do not involve cryptocurrency movement. Instead, they offer a signal for the malware to follow, enabling it to contact the server for further instructions or updates.

Implications and Countermeasures

This sophisticated approach highlights a growing trend of utilizing blockchain technology for malicious purposes. The Ethereum route ensures the malware can locate new server addresses, even if primary channels are disrupted. This resilience complicates efforts to fully eradicate the threat.

To mitigate such risks, Ransom-ISAC advises monitoring for unusual Ethereum block queries and server connections. Security teams should also scrutinize Node.js processes and developer environments for signs of compromise. Simply removing a known server is insufficient if the malware can quickly adapt by locating new servers via blockchain signals.

As cyber threats continue to evolve, organizations must remain vigilant and adopt proactive measures to safeguard against innovative attack vectors leveraging blockchain technology.

Cyber Security News Tags:Blockchain, credential stealer, Cryptocurrency, cyber threats, Cybersecurity, Ethereum, Malware, North Korea, Ransom-ISAC, remote access

Post navigation

Previous Post: Pentagon Data Breach Affects Over 3 Million Individuals
Next Post: New BTR Attack Compromises Linux Despite Defenses

Related Posts

Anthropic’s Claude Mythos Preview Revolutionizes Zero-Day Detection Anthropic’s Claude Mythos Preview Revolutionizes Zero-Day Detection Cyber Security News
Critical Chrome 0-Day Flaws Demand Immediate Action Critical Chrome 0-Day Flaws Demand Immediate Action Cyber Security News
New Magecart Attack Inject Malicious JavaScript to Skim Payment Data New Magecart Attack Inject Malicious JavaScript to Skim Payment Data Cyber Security News
New Report Uncover That Chinese Hackers Attempted To Compromise SentinelOne’s Own Servers New Report Uncover That Chinese Hackers Attempted To Compromise SentinelOne’s Own Servers Cyber Security News
Threat Actors Weaponizing Visual Studio Code to Deploy a Multistage Malware Threat Actors Weaponizing Visual Studio Code to Deploy a Multistage Malware Cyber Security News
IRGC-Linked APT35 Structure, Tools, and Espionage Operations Disclosed IRGC-Linked APT35 Structure, Tools, and Espionage Operations Disclosed Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Silver Fox Hackers Exploit Fake Software Sites for Malware
  • Spectre v2 Variant Puts Intel, AMD, Arm CPUs at Risk
  • New BTR Attack Compromises Linux Despite Defenses
  • Ethereum Used for Covert Malware Communication
  • Pentagon Data Breach Affects Over 3 Million Individuals

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Silver Fox Hackers Exploit Fake Software Sites for Malware
  • Spectre v2 Variant Puts Intel, AMD, Arm CPUs at Risk
  • New BTR Attack Compromises Linux Despite Defenses
  • Ethereum Used for Covert Malware Communication
  • Pentagon Data Breach Affects Over 3 Million Individuals

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark