Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'blockchain c2'

View all threats tagged with 'blockchain c2'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: blockchain c2

Threats Tagged 'blockchain c2'

Click on any threat for detailed analysis and mitigation recommendations

Ten Minutes to Containment: How Agentic MXDR Scoped a Fake Claude Desktop Intrusion
0

This threat describes a FakeAgent intrusion campaign discovered through an automated threat hunting agent within ten minutes. The campaign used malvertising on Bing to distribute trojanized Claude Desktop installers hosted on legitimate Anthropic infrastructure. The attack chain involved DLL sideloading via Java Chromium Embedded Framework, tampering with Microsoft Defender, scheduled task persistence disguised as Microsoft Edge updates, and blockchain-based command-and-control infrastructure using EtherHiding techniques. The intrusion deployed SectopRAT malware, which has infostealing and remote desktop capabilities, necessitating full endpoint reimaging and credential resets.

Join the discussion
Tracking PavinLoader across ClickFix and fake download campaigns
0

A sophisticated multi-stage loader dubbed PavinLoader has been identified across multiple distribution campaigns including ClickFix attacks, fake software downloads, and malicious RenPy games. The loader employs heavily obfuscated .NET DLLs, abuses legitimate Windows tools like MSBuild, and utilizes EtherHiding technique to retrieve command-and-control domains via blockchain. The infection chain consists of four main stages: a Loader DLL performing anti-forensics, an EtherHiding Loader obtaining C2 infrastructure, an Anti-Analysis DLL checking for virtualized environments, and a PE Loader delivering final payloads including Amatera Stealer. Evidence suggests PavinLoader may be offered as a Loader-as-a-Service, with common artifacts found across over 200 related files. The campaigns demonstrate sophisticated evasion techniques including custom obfuscation, API hashing, and extensive anti-analysis checks targeting virtualized environments and specific geographic regions.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: blockchain c2
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses