Trusted Design

EtherHiding Exposed: Inside a Blockchain-powered Malware Campaign Hiding in Plain Sight

概要

A sophisticated malware campaign active since November 2025 exploits blockchain technology to maintain persistent command-and-control infrastructure. Attackers store C2 addresses in Polygon blockchain smart contracts rather than hardcoding them, enabling rapid infrastructure rotation for pennies. The operation compromised at least 31 legitimate websites across multiple countries, deploying FakeCaptcha lures through compromised sites accessed via Bing or Google searches. When victims follow the lure, malware establishes persistence through scheduled tasks and registry keys, queries Polygon smart contracts for current C2 domains, and deploys versatile payloads including banking trojans targeting 479 financial and cryptocurrency domains. Investigators identified 15 smart contracts across six operational waves, three active C2 domains, and two operator wallets controlling the infrastructure. The campaign demonstrates significant operational security with multiple fallback mechanisms, though investigators succe...

Created: 2026-09-18

Indicators

Indicatorsは見つかっていない。

類似Pulses

類似するPulseは見つかりませんでした。

このPulseに関連する脅威アクター (事実ベース)

事実ベースの脅威アクターは見つかりませんでした。

このPulseに関連する脅威アクター (推論ベース)

推論ベースの脅威アクターは見つかりませんでした。

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る