logo

Cross-Chain TxDataHiding Crypto Heist: A Very Chainful Process (Part 1)

ID: 456cda66-6dea-54a0-81fe-550ca03f4789

STIX ID: report--456cda66-6dea-54a0-81fe-550ca03f4789

Feed Name: Ransomware ISAC Blog

Threat Score
85/100

Date Published: 2025-10-20

Date Updated: 2026-04-19

Author: [email protected] (Ellis Stannard)

...
...

Ransom-ISAC analysed a malicious GitHub repository used in a DPRK-linked fake job social engineering campaign that weaponised obfuscated JavaScript to implement a novel Cross-Chain TxDataHiding C2: TRON/Aptos act as index chains pointing to encrypted payloads on BSC. The report details the multi-stage retrieval and XOR/character-shuffle deobfuscation, provides IoCs (transaction hashes, wallet addresses, sample SHA256), YARA rules, detection tooling, and warns that this takedown-resistant, low-cost blockchain C2 significantly raises analysis and mitigation complexity for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.