DPRK Hackers Added HashHiding to C2 Infrastructure
The new technique utilizes the Ethereum blockchain to mask command-and-control communications.
Updated on Sept. 29, 2026 in Cybersecurity

Live Poll
Do you believe the expansion of blockchain technology makes our digital infrastructure less secure?
State-linked hackers from the DPRK have integrated a new method called HashHiding into their blockchain-backed command-and-control infrastructure. This technique acts as an Ethereum-based recovery channel to help maintain persistent access to infected systems.
Why it matters
The implementation of HashHiding provides a resilient method for maintaining malware infrastructure that is highly resistant to standard takedown attempts. By leveraging a decentralized ledger, attackers can bypass traditional domain-based security filtering.
The HashHiding technique embeds command-and-control server IP addresses and port numbers directly within Ethereum transfer recipient addresses. This eliminates the need for attackers to rely on traceable domains or complex smart contracts to communicate with compromised machines.
The players
DPRK
A state actor known for utilizing sophisticated cyber operations and financial theft to circumvent international sanctions.
The details
The mechanism functions by turning the Ethereum blockchain into a covert communication bus. Infected systems continuously scan the transaction history of the blockchain to locate specific transfer recipient fields containing encoded connection data. Once identified, the malware parses these hexadecimal strings to extract updated server infrastructure details, allowing the attacker to regain control even if their primary infrastructure is blocked.
Timeline
September 2026: The HashHiding technique was officially identified in active campaigns.
The Tech Race
This development marks a shift toward decentralized command-and-control architectures by utilizing public ledgers as communication channels. It follows a broader trend where threat actors move away from centralized infrastructure that is susceptible to administrative seizure.
Security administrators must now account for traffic monitoring that includes analysis of blockchain transaction patterns. Traditional firewall rules based on domain reputations will not be effective against this method of infrastructure recovery.
The takeaway
The move to use Ethereum for command-and-control signals that attackers are successfully exploiting the permanency of blockchain ledgers to secure their communication. Security teams should monitor internal network logs for anomalous traffic patterns interacting with cryptocurrency network interfaces.
Further reading
For more on evolving threat actor techniques, see our Cybersecurity section.
Live Poll
Do you believe the expansion of blockchain technology makes our digital infrastructure less secure?






