A North Korean malware operation has devised a method to maintain its infected machines' connectivity to its operators This article explores ransom isac revealed. . By embedding the control server's location within cryptocurrency transfers, the attackers sidestep the need to store the malware on the Ethereum blockchain.
The campaign targets developers through deceptive job postings, tainted code repositories, and malicious software packages. Ransom-ISAC revealed in a report shared with ZeroOwl (ZeroOwl) that the malware employs a new technique to maintain its operator's identity even when communication channels are blocked. Unlike these transactions, which often include smart contract calls or hidden scripts, these transfers carry no smart contract calls or hidden scripts.
It scans recent Ethereum blocks through public access points, identifying matching transfers, decoding the recipient addresses, and contacting the servers that reveal these addresses. Ransom-ISAC suggests keeping an eye on unexpected Ethereum block queries followed by unusual server connections, and monitoring the signaling wallet for new destination changes. Indicators of Compromise (IoCs): - **C2 Address**: 23[.]27[.]20[.
]143:27017 (Campaign October 2025) - **C2 Endpoint 1**: 23[.]27[.]20[. ]187:80 (Ethereum-encoded destination) - **C2 Endpoint 2**: 23[.]27[.]20[. ]187:443 (Ethereum-encoded destination) - **C2 Endpoint 3**: 181[.]214[.]149[. ]147:443 (Ethereum-encoded destination) - **C2 Endpoint 4**: 181[.]214[.]149[.
]148:443 (Ethereum-encoded destination; also describes a port 80 dropper path on this IP) Encoded Ethereum recipient 0x171B14bB0050171b14Bb01BB398EAAB6441Fbd47 was the first destination, encoding the port 80 C2 endpoint. XOR key 2\[gWfGj;<:-93Z^C.










