logo

Cross-Chain TxDataHiding Crypto Heist: A Very Chainful Process (Part 3)

ID: 58669b24-4a9d-5b62-b266-a87c425c7cee

STIX ID: report--58669b24-4a9d-5b62-b266-a87c425c7cee

Feed Name: Ransomware ISAC Blog

Threat Score
85/100

Date Published: 2025-11-13

Date Updated: 2026-07-29

Author: [email protected] (Yashraj Solanki)

...
...

Executive summary: Part 3 of an investigative series details a sophisticated intrusion leveraging a private weaponised GitHub repository and NPM supply-chain compromises to deploy cross-platform malware and blockchain-based C2, with infrastructure clusters identified across multiple ASNs (notably Evoxt Enterprise) and C2 channels (HTTP API on DB ports and socket.io over 443/3306). The report provides infrastructure fingerprints, cluster mappings (Cluster-1..4, Cluster-X-RDP, Cluster-X-302), C2 URL paths, socket.io response fingerprints, YARA rules and file hashes, and extensive IOCs (IP addresses, ASNs, certificate CNs), and assesses possible DPRK-aligned involvement while noting attribution confidence limitations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.