News Room
16
Share
Swiss Federal Authorities Probe Sophisticated SharePoint Breach Linked to NullReceiver Blockchain C2 Tactic
highCyber Espionage

Swiss Federal Authorities Probe Sophisticated SharePoint Breach Linked to NullReceiver Blockchain C2 Tactic

Investigations into a breach of Swiss government SharePoint accounts reveal a novel NullReceiver blockchain-based command-and-control mechanism. The campaign compromised over 200 accounts.

10 August 2026Last updated 18 August 20265 min readPalo Alto Unit 42
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Cyber Espionage
Severity:
High
Actor Type:
APT
Geography:
Europe
Confidence:
High Confidence
Source:
Palo Alto Unit 42
Read Time:
5 min

Executive Summary On August 7, 2026, the Swiss Federal Department of Defence, Civil Protection and Sport (DDPS) confirmed a sophisticated cyber espionage operation targeting its SharePoint infrastructure. Initial forensic analysis suggests that approximately 200 user accounts were compromised, with sensitive administrative data likely exfiltrated. This incident coincides with the emergence of the 'NullReceiver' tactic, a novel blockchain-based command-and-control (C2) method that allows attackers to remain undetected by traditional network security filters. The campaign represents a significant escalation in the technical capabilities of state-aligned actors operating within the European theater. As of August 10, 2026, federal investigators are working with international partners to determine the full extent of the data loss and the identity of the perpetrators. ## Threat Analysis The threat actors appear to have gained initial access through a supply chain compromise involving trojanized npm packages. These packages were specifically designed to target developers working on government-adjacent projects. Once the malicious code was executed within the environment, the attackers moved laterally to the SharePoint servers. The primary objective of the campaign is the collection of strategic intelligence related to Swiss national security and diplomatic communications. Unlike typical ransomware attacks, there was no attempt at data encryption or extortion; the actors maintained a low profile, focusing on persistent access and silent data harvesting over several weeks. The precision of the targeting suggests a high degree of reconnaissance prior to the initial breach. ## Technical Details The core of this operation is the 'NullReceiver' tactic, an evolution of the 'EtherHiding' technique. In this method, the malware does not communicate with a fixed IP address or domain. Instead, it queries the Ethereum blockchain for specific 'empty' transactions. The C2 server's IP address is encoded within the 'To' address field of a transaction that transfers zero ETH. Because these transactions are legitimate parts of the blockchain ledger, they are not flagged by standard firewalls or secure web gateways. The malware decodes the destination address to reconstruct the C2 IP, allowing it to receive instructions and exfiltrate data. This fileless approach, combined with the use of encrypted plugins (AES-256), ensures that the malware resides primarily in memory, leaving minimal traces on the physical disk. Furthermore, the malware utilizes a modified scripting engine to execute commands, making it highly resistant to static analysis. ## Attribution Assessment While the Swiss government has not officially named a culprit, threat intelligence firms like Unit 42 and Microsoft MSTIC have noted similarities between this campaign and previous activities by the 'Silver Dragon' APT. The group has a history of targeting European government and military entities. Additionally, the use of the 'NullReceiver' tactic has been linked to 'ExfilSquad,' a recently identified collective known for its high-level technical ingenuity and focus on strategic espionage. The complexity of the blockchain-based C2 infrastructure suggests a well-funded, nation-state-backed operation rather than a decentralized hacktivist group. The focus on neutral European nations indicates a shift in geopolitical targeting. ## Implications The successful breach of Swiss government systems underscores the persistent risk posed by advanced persistent threats to neutral nations. The use of blockchain for C2 represents a paradigm shift in network defense, as it leverages decentralized, immutable infrastructure to bypass centralized security controls. This incident is likely to prompt a review of cloud security protocols across European government agencies, particularly regarding the use of third-party collaboration tools like SharePoint and the security of the software supply chain. The potential for competitive intelligence risks is high, as the stolen data could provide adversaries with insights into Swiss defense strategies and international diplomatic positions. ## Recommendations Organizations are advised to implement the following measures: 1. Enhance monitoring for anomalous outbound traffic to known blockchain explorers and nodes. 2. Implement strict code-signing requirements and audit all third-party npm packages used in development environments. 3. Transition to a Zero Trust architecture with granular conditional access policies for all cloud-based collaboration platforms. 4. Utilize advanced endpoint detection and response (EDR) tools capable of detecting fileless, memory-resident threats and anomalous system command contexts. 5. Conduct regular threat hunting exercises focused on identifying unauthorized access to administrative accounts within cloud environments.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo