North Korean threat actors have been linked to the NullReceiver campaign, which uses trojanized npm packages to deploy malware that decodes C2 IP addresses from Ethereum transactions. This activity is part of a broader pattern of using blockchain-based techniques for command-and-control, as seen in the Contagious Interview campaign.