Cross-Chain TxDataHiding Crypto Heist: A Very (Very) Chainful Process (Part 4)
ID: d00885da-b984-54e9-ac5c-16a0123eea90
STIX ID: report--d00885da-b984-54e9-ac5c-16a0123eea90
Feed Name: Ransomware ISAC Blog
Date Published: 2025-12-08
Date Updated: 2026-04-19
Author: [email protected] (Nick Smart and Andrii Sovershennyi)
Executive summary: Ransom‑ISAC (with Crystal Intelligence and collaborators) investigated a September 2025 cryptocurrency and data-theft campaign likely linked to DPRK financial cyber operations, revealing a multi-stage attack that used phishing to seed a private weaponised GitHub repository, cross-chain TxDataHiding to deliver obfuscated payloads on public blockchains, takedown‑resistant blockchain-based C2 and downloaders that deployed OmniStealer and DEV#POPPER.JS RAT variants; the report provides timeline analysis, IOCs (IPs, wallet addresses, transaction hashes, malware SHA256s), on-chain fund tracing across TRON, BSC and other chains, and contextual attribution details including a Russian IP overlap and laundering patterns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
