Cross-Chain TxDataHiding Crypto Heist: A Very Chainful Process (Part 3)
ID: 58669b24-4a9d-5b62-b266-a87c425c7cee
STIX ID: report--58669b24-4a9d-5b62-b266-a87c425c7cee
Feed Name: Ransomware ISAC Blog
Executive summary: Part 3 of an investigative series details a sophisticated intrusion leveraging a private weaponised GitHub repository and NPM supply-chain compromises to deploy cross-platform malware and blockchain-based C2, with infrastructure clusters identified across multiple ASNs (notably Evoxt Enterprise) and C2 channels (HTTP API on DB ports and socket.io over 443/3306). The report provides infrastructure fingerprints, cluster mappings (Cluster-1..4, Cluster-X-RDP, Cluster-X-302), C2 URL paths, socket.io response fingerprints, YARA rules and file hashes, and extensive IOCs (IP addresses, ASNs, certificate CNs), and assesses possible DPRK-aligned involvement while noting attribution confidence limitations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
