Ethical Hacking News
The world of cybersecurity has been shaken by the emergence of a sophisticated cyber espionage technique known as NullReceiver. This article delves into the details of this technique, its evolution, and its potential implications on the cybersecurity landscape.
Learn how NullReceiver is changing the game for hackers and security experts alike, and what it means for your organization's online security.
The NullReceiver technique is a sophisticated cyber espionage method used by North Korean hacking groups to decode C2 IP addresses from blockchain data. The technique involves embedding malicious code within a smart contract on a public blockchain, making it difficult for defenders to detect. NullReceiver is an evolution of the EtherHiding technique, which was first publicly documented in October 2023. The technique provides a non-existent destination address, making attribution difficult and more sneaky compared to previous methods. Cybersecurity researchers are flagging the use of NullReceiver as a growing concern that requires continued vigilance and awareness among defenders.
The world of cybersecurity is constantly evolving, and new threats emerge every day. In recent times, researchers have discovered a sophisticated cyber espionage technique known as NullReceiver, which employs the NullReceiver tactic to decode the C2 (Command and Control) IP address from blockchain data. This article will delve into the details of this technique, its evolution, and its potential implications on the cybersecurity landscape.
The use of blockchain-based command-and-control (C2) techniques has been a growing concern in recent years. These techniques allow attackers to conceal their C2 server IP addresses inside a made-up destination address of a completely empty Ethereum transfer. The new dead drop resolver approach, observed in two trojanized npm packages "bianira-ui" and "fluid-type-ui," has been codenamed NullReceiver by OpenSourceMalware.
NullReceiver is considered an evolution of the EtherHiding blockchain-based C2 technique, which was first publicly documented by Guardio Labs in October 2023. The original technique involved embedding nefarious code within a smart contract on a public blockchain like BNB Smart Chain (BSC) or Ethereum. This made it difficult for defenders to detect as the code would appear to be part of the legitimate smart contract.
The use of NullReceiver is linked to North Korean hacking groups, which have been known to employ sophisticated cyber espionage techniques. The latest development in this regard indicates that the threat actors are further refining their tactics and making it increasingly difficult for defenders to detect.
According to security researcher Paul McCarty, "NullReceiver encodes the C2 IP directly in the bytes of the recipient address of a zero-value, zero-data Ethereum transfer." This technique aims to address one of the major shortcomings of EtherHiding, which requires a fixed, publicly known destination address that can be tracked by defenders as new transactions containing the payload or the malicious script occur for a gas fee.
The NullReceiver technique provides a non-existent destination address, making attribution difficult. The entire sequence of actions on a victim machine is as follows - look up a hard-coded attacker wallet, find its most recent outbound transaction, read that transaction's destination address, decode a C2 IP address directly out of the address bytes by converting the first four bytes from their hexadecimal representation to their number equivalent, and connect to that IP address.
An examination of the wallet transactions shows that the destination "To" address for each of them is the same. While "a658863e" becomes "166.88.134[.]62," the trailing bytes "68656c6c6f6970626f742121" represent the ASCII string "helloipbot!!." This highlights the complexity and sophistication of the NullReceiver technique.
The absence of a fixed target and fingerprint, along with cheaper transactions, makes NullReceiver more sneaky. The technique never reuses a destination address; every lookup is a brand-new, throwaway address that's never been seen before. A NullReceiver transaction carries nothing extra at all; there's no field to fingerprint because there's no field.
Cybersecurity researchers have flagged the use of NullReceiver by North Korean hacking groups as a growing concern. The technique's sophistication and potential implications on the cybersecurity landscape cannot be overstated. As with any emerging threat, it is essential for defenders to remain vigilant and stay updated on the latest intelligence.
In conclusion, the evolution of NullReceiver represents a significant development in the world of cyber espionage. Its sophistication and potential impact on the cybersecurity landscape underscore the need for continued vigilance and awareness among defenders. It is crucial to stay informed about emerging threats like NullReceiver and to adopt proactive measures to mitigate their effects.
Summary:
The NullReceiver technique, an evolution of EtherHiding, employs a sophisticated NullReceiver tactic to decode C2 IP addresses from blockchain data. Linked to North Korean hacking groups, this technique provides a non-existent destination address, making attribution difficult. With its absence of a fixed target and fingerprint, along with cheaper transactions, NullReceiver is considered a more sneaky threat. Cybersecurity researchers are flagging the use of NullReceiver as a growing concern that requires continued vigilance and awareness among defenders.
Related Information:
https://www.ethicalhackingnews.com/articles/The-Evolution-of-NullReceiver-A-Sophisticated-Cyber-Espionage-Technique-Employing-NullReceiver-Tactic-to-Decode-C2-IP-from-Blockchain-ehn.shtml
https://thehackernews.com/2026/08/trojanized-npm-packages-decode-c2-ip.html
Published: Wed Aug 5 12:22:22 2026 by llama3.2 3B Q4_K_M