Threats Tagged 'blockchain c2'
View all threats tagged with 'blockchain c2'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'blockchain c2'
Click on any threat for detailed analysis and mitigation recommendations
Ten Minutes to Containment: How Agentic MXDR Scoped a Fake Claude Desktop Intrusion 0 This threat describes a FakeAgent intrusion campaign discovered through an automated threat hunting agent within ten minutes. The campaign used malvertising on Bing to distribute trojanized Claude Desktop installers hosted on legitimate Anthropic infrastructure. The attack chain involved DLL sideloading via Java Chromium Embedded Framework, tampering with Microsoft Defender, scheduled task persistence disguised as Microsoft Edge updates, and blockchain-based command-and-control infrastructure using EtherHiding techniques. The intrusion deployed SectopRAT malware, which has infostealing and remote desktop capabilities, necessitating full endpoint reimaging and credential resets. Join the discussion | AlienVault OTX General | 08/24/2026, 21:19:19 UTC Added: 08/26/2026, 13:07:12 UTC |
Tracking PavinLoader across ClickFix and fake download campaigns 0 A sophisticated multi-stage loader dubbed PavinLoader has been identified across multiple distribution campaigns including ClickFix attacks, fake software downloads, and malicious RenPy games. The loader employs heavily obfuscated .NET DLLs, abuses legitimate Windows tools like MSBuild, and utilizes EtherHiding technique to retrieve command-and-control domains via blockchain. The infection chain consists of four main stages: a Loader DLL performing anti-forensics, an EtherHiding Loader obtaining C2 infrastructure, an Anti-Analysis DLL checking for virtualized environments, and a PE Loader delivering final payloads including Amatera Stealer. Evidence suggests PavinLoader may be offered as a Loader-as-a-Service, with common artifacts found across over 200 related files. The campaigns demonstrate sophisticated evasion techniques including custom obfuscation, API hashing, and extensive anti-analysis checks targeting virtualized environments and specific geographic regions. Join the discussion | AlienVault OTX General | 08/25/2026, 07:12:42 UTC Added: 08/25/2026, 10:52:01 UTC |
Showing 1 to 2 of 2 results