North Korea's Alluring Pisces Uses Blockchain for C2

North Korean Hackers Use Public Blockchain for Covert C2 Channel

CRITICAL
October 8, 2026
6m read
Threat ActorSupply Chain AttackCloud Security

Related Entities

Threat Actors

Alluring PiscesSapphire Sleet

Products & Tech

Other

ChainDropPolinRiderShai-Hulud

Full Report

Executive Summary

The North Korean state-sponsored threat group Alluring Pisces (tracked by Microsoft as Sapphire Sleet) has adopted a groundbreaking and highly resilient technique for command-and-control (C2) communications. Research from Palo Alto Networks' Unit 42 reveals the group is leveraging public blockchains to host its C2 infrastructure. This method, used in sophisticated software supply chain attacks, makes the C2 channel exceptionally resistant to traditional disruption efforts like domain seizures or IP blocklisting. The group uses this technique in campaigns targeting open-source ecosystems like npm and Rust to steal cloud credentials from enterprise build environments, posing a severe threat to cloud security.

Threat Overview

Alluring Pisces specializes in software supply chain attacks that poison open-source packages. The goal is to have their malicious code executed within trusted environments, such as a developer's workstation or an automated CI/CD pipeline, to steal credentials.

Two notable campaigns employing this blockchain C2 technique are:

  1. ChainDrop: A self-propagating worm from the Shai-Hulud malware family that has infected over 400 npm packages. It uses a preinstall hook to activate a credential harvester.
  2. PolinRider: A related campaign that spreads across multiple package ecosystems, including npm, Go modules, and Packagist. This campaign hides loaders in repository configuration files (devcontainer.json) and IDE settings, causing the payload to execute when a developer simply opens the compromised project.

In both cases, once the malware is active, it steals cloud IAM keys and CI/CD worker tokens. It then needs to receive instructions from the attackers. Instead of connecting to a hardcoded domain or IP address, the malware queries a smart contract on a public blockchain to retrieve the current C2 server address. This address can be updated by the attackers at any time by interacting with the smart contract, while the C2 resolution mechanism itself remains decentralized and uncensorable.

Technical Analysis

The use of a public blockchain for C2 is a significant evolution in threat actor tradecraft. It solves a major operational problem for attackers: C2 infrastructure is often the weakest link and the primary target for defenders and law enforcement.

How it Works (Analyst Assessment)

  1. Deployment: The attackers deploy a simple smart contract to a public blockchain (e.g., Ethereum, BNB Smart Chain).
  2. Storage: The smart contract contains a variable where the attackers can store a string, such as an IP address, domain name, or onion address.
  3. Update Function: The contract has a function, protected by the attacker's private key, that allows them to update the stored C2 address.
  4. Query Function: The contract has a public, permissionless function that allows anyone (including the malware) to read the currently stored C2 address.
  5. Malware Logic: The malware is hardcoded with the address of the smart contract and the name of the query function. When it needs to phone home, it connects to a public blockchain node, calls the function, retrieves the C2 address, and then initiates communication with the attacker's server.

This makes the C2 mechanism as resilient as the blockchain itself. There is no central domain to seize or IP to blocklist to disrupt the resolution process. Defenders would have to block access to the entire blockchain, which is often infeasible.

MITRE ATT&CK Techniques

Impact Assessment

The primary impact is the theft of high-value cloud credentials, which can lead to a complete compromise of an organization's cloud environment. Attackers can use these credentials to exfiltrate sensitive data, deploy ransomware, or use the victim's infrastructure for their own purposes. The use of a blockchain-based C2 makes these campaigns more persistent and harder to eradicate. It forces defenders to shift their focus from blocking C2 infrastructure to detecting the malware's activity on the endpoint and within the build pipeline itself. This tactic raises the bar for defenders and demonstrates the continuous innovation of sophisticated state-sponsored threat actors.

IOCs — Directly from Articles

No specific indicators of compromise were provided in the source articles.

Cyber Observables — Hunting Hints

To hunt for this type of activity, security teams should focus on build environments:

Type
Network Traffic Pattern
Value
Outbound connections to public blockchain nodes/APIs (e.g., Infura, Alchemy)
Description
Build servers or developer workstations making unexpected connections to blockchain gateways.
Type
File Path
Value
.devcontainer/devcontainer.json
Description
The PolinRider campaign hides loaders in this file. Monitor for suspicious commands or scripts.
Type
Process Name
Value
npm, go, composer
Description
Monitor processes associated with package managers for anomalous network activity or file access.
Type
Log Source
Value
CI/CD pipeline logs
Description
Scrutinize logs for installations of known poisoned packages like keyv and cacheable-request or any package with a preinstall hook.

Detection & Response

Detection:

  1. Egress Filtering: This is the most effective detection method. Strictly control and monitor outbound network traffic from CI/CD runners and developer environments. Connections to public blockchain APIs should be heavily scrutinized and likely blocked by default. (D3FEND: D3-OTF: Outbound Traffic Filtering)
  2. Dependency Analysis: Use SCA tools to identify and flag packages with preinstall scripts or other high-risk features. Maintain a private registry of vetted packages. (D3FEND: D3-FA: File Analysis)
  3. Behavioral Analysis: In sandboxed build environments, monitor for processes attempting to read sensitive files (~/.aws/credentials, ~/.ssh/id_rsa) or making unexpected network connections.

Response:

  1. Isolate Environment: Immediately isolate the compromised build runner or developer machine.
  2. Rotate All Credentials: Assume all secrets within the environment are compromised and initiate a full rotation.
  3. Audit Source Code: Scan all source code for the presence of the malicious packages and remove them.

Mitigation

  • Secure the Build Pipeline: Harden CI/CD environments by applying the principle of least privilege. Build jobs should run with ephemeral, short-lived credentials that have the minimum scope necessary. (M1026: Privileged Account Management)
  • Network Isolation: Whenever possible, run build jobs in an environment with no or limited internet access. If internet access is required, use an explicit proxy and allowlist only the necessary domains (e.g., package registries, internal artifactories). (D3FEND: D3-NI: Network Isolation)
  • Developer Training: Educate developers on the risks of supply chain attacks and the danger of preinstall scripts and suspicious project configurations.

Timeline of Events

1
October 8, 2026
This article was published

MITRE ATT&CK Mitigations

Implement strict egress filtering on build environments to block connections to blockchain APIs and other non-essential services.

Run build jobs in isolated, ephemeral containers with no access to persistent credentials or sensitive parts of the network.

Use short-lived, narrowly-scoped credentials for CI/CD pipelines to limit the value of stolen tokens.

Audit

M1047enterprise

Continuously audit and monitor CI/CD logs for suspicious activities like unexpected package installations or network connections.

Sources & References

North Korea Runs Cloud Supply Chain Attacks Through the Blockchain, Unit 42 Finds
Cybersecurity Insiders (cybersecurity-insiders.com) •October 8, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

alluring piscessapphire sleetdprkblockchainc2supply chaincloud securityunit 42

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.