CyberSecurityBoardThreat Intel · CVEs · Products
Attack Groups

North Korean Cyber Operations Linked to NullReceiver

June 29, 2026

North Korean threat actors have been linked to the NullReceiver campaign, which uses trojanized npm packages to deploy malware that decodes C2 IP addresses from Ethereum transactions. This activity is part of a broader pattern of using blockchain-based techniques for command-and-control, as seen in the Contagious Interview campaign.