The North Korean state-sponsored threat group Alluring Pisces (tracked by Microsoft as Sapphire Sleet) has adopted a groundbreaking and highly resilient technique for command-and-control (C2) communications. Research from Palo Alto Networks' Unit 42 reveals the group is leveraging public blockchains to host its C2 infrastructure. This method, used in sophisticated software supply chain attacks, makes the C2 channel exceptionally resistant to traditional disruption efforts like domain seizures or IP blocklisting. The group uses this technique in campaigns targeting open-source ecosystems like npm and Rust to steal cloud credentials from enterprise build environments, posing a severe threat to cloud security.
Alluring Pisces specializes in software supply chain attacks that poison open-source packages. The goal is to have their malicious code executed within trusted environments, such as a developer's workstation or an automated CI/CD pipeline, to steal credentials.
Two notable campaigns employing this blockchain C2 technique are:
preinstall hook to activate a credential harvester.devcontainer.json) and IDE settings, causing the payload to execute when a developer simply opens the compromised project.In both cases, once the malware is active, it steals cloud IAM keys and CI/CD worker tokens. It then needs to receive instructions from the attackers. Instead of connecting to a hardcoded domain or IP address, the malware queries a smart contract on a public blockchain to retrieve the current C2 server address. This address can be updated by the attackers at any time by interacting with the smart contract, while the C2 resolution mechanism itself remains decentralized and uncensorable.
The use of a public blockchain for C2 is a significant evolution in threat actor tradecraft. It solves a major operational problem for attackers: C2 infrastructure is often the weakest link and the primary target for defenders and law enforcement.
This makes the C2 mechanism as resilient as the blockchain itself. There is no central domain to seize or IP to blocklist to disrupt the resolution process. Defenders would have to block access to the entire blockchain, which is often infeasible.
T1195.002 - Compromise Software Supply Chain: The primary initial access vector is poisoning open-source software packages.T1071 - Application Layer Protocol: The use of a blockchain for C2 is a novel form of this technique, abusing a legitimate application-layer service for malicious communication.T1573.002 - Asymmetric Cryptography: The smart contract is controlled via the attacker's private key, an example of using asymmetric cryptography for C2.T1552.005 - Cloud Credentials: The primary goal of the malware is to steal cloud IAM keys and CI/CD tokens.The primary impact is the theft of high-value cloud credentials, which can lead to a complete compromise of an organization's cloud environment. Attackers can use these credentials to exfiltrate sensitive data, deploy ransomware, or use the victim's infrastructure for their own purposes. The use of a blockchain-based C2 makes these campaigns more persistent and harder to eradicate. It forces defenders to shift their focus from blocking C2 infrastructure to detecting the malware's activity on the endpoint and within the build pipeline itself. This tactic raises the bar for defenders and demonstrates the continuous innovation of sophisticated state-sponsored threat actors.
No specific indicators of compromise were provided in the source articles.
To hunt for this type of activity, security teams should focus on build environments:
.devcontainer/devcontainer.jsonnpm, go, composerCI/CD pipeline logskeyv and cacheable-request or any package with a preinstall hook.Detection:
D3-OTF: Outbound Traffic Filtering)preinstall scripts or other high-risk features. Maintain a private registry of vetted packages. (D3FEND: D3-FA: File Analysis)~/.aws/credentials, ~/.ssh/id_rsa) or making unexpected network connections.Response:
D3-NI: Network Isolation)preinstall scripts and suspicious project configurations.Implement strict egress filtering on build environments to block connections to blockchain APIs and other non-essential services.
Run build jobs in isolated, ephemeral containers with no access to persistent credentials or sensitive parts of the network.
Use short-lived, narrowly-scoped credentials for CI/CD pipelines to limit the value of stolen tokens.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.