sudo rm -rf --no-preserve-root /|Sep 18, 2026 10:29
so remember when certain DPRK groups stored their C2 infra details (often base64-encoded & XOR-encrypted) in smart contracts? it was called EtherHiding. well, our PolinRider "friends" (and other groups) have gotten a bit more "creative". they now use a new pattern called "NullReceiver": simply put, they send a zero-value tx with zero calldata, while hiding the C2 IP address directly in the `to` address lol. let's take real-world example:
- tx hash: `0x910d35c6620bea357c867bd93b291dc6feb1990bb57a0a063fa652cd29d096b2`
- `to` address: `0xa658863ea658863e68656c6c6f6970626f742121`
this will lead to
- a658863e -> 166[.]88[.]134[.]62
- a658863e -> repetition of the above IP
- the rest (68656c6c6f6970626f742121) is some string "helloipbot!!"
Share To
HotFlash
APP
X
Telegram
CopyLink