Cross-Chain TxDataHiding Crypto Heist: A Very Chainful Process (Part 2)
ID: b3296fc1-c108-5890-9c1f-4745e45929c0
STIX ID: report--b3296fc1-c108-5890-9c1f-4745e45929c0
Feed Name: Ransomware ISAC Blog
This report documents a sophisticated, multi-stage campaign (attributed to DPRK-affiliated actors) that compromises developers via social engineering and weaponised GitHub repositories to deliver a cross-platform JavaScript RAT (DEV#POPPER.js) and a Python info-stealer (OmniStealer). The attackers use an advanced Cross-Chain TxDataHiding C2 mechanism (TRON/Aptos indexing + BSC payload storage), extensive obfuscation/anti-analysis techniques, IDE (VSCode/Cursor) injection for persistence, and dual C2 infrastructures to exfiltrate credentials, wallets, environment secrets, and source code; the report provides hashes, network IOCs, blockchain addresses, YARA rules, and detection guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
