Skip to main content

Threats Tagged 'etherhiding'

View all threats tagged with 'etherhiding'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: etherhiding

Threats Tagged 'etherhiding'

Click on any threat for detailed analysis and mitigation recommendations

Over a five-month period, multiple malicious campaigns operated through a single bulletproof hosting provider, AS202412 (OMEGATECH LTD, Seychelles). These campaigns used disposable domains, fake CAPTCHA pages to trick victims into executing commands, and varied infrastructure including compromised websites, cloud storage, blockchain-based C2 addresses, and trojanized installers. Despite differing payloads and methods, all campaigns initiated contact via the same hosting provider. Successful infections deployed stealers and remote access tools with persistence across reboots. Most browser visits ended at the lure page without execution.

Join the discussion

Blackpoint's Adversary Pursuit Group identified ChainScript, a previously unnamed Node.js remote access trojan discovered during ClickFix investigation. The malware disguises itself as legitimate software including Spotify, Zoom Workplace, and Microsoft Teams through malicious Windows Installer packages. ChainScript employs an EtherHiding-style C2 discovery technique utilizing a Polygon smart contract to dynamically locate active WebSocket infrastructure, enabling operators to rotate backend services without rebuilding agents. The RAT provides comprehensive remote access capabilities including interactive shell sessions, file operations, screenshots, payload deployment, cryptocurrency wallet discovery, remote JavaScript execution, self-update mechanisms, and cleanup functions. Multiple builds appeared under different names (ComponentTask33, UpdateDigital, HostShared, OrchidViolet66) while maintaining consistent core agent architecture. Analysis revealed automated contract deployment integrated into the mal...

Join the discussion

In June 2026, a new malware family named SloppyRAT was identified, likely used by ransomware-related threat actors to establish footholds for lateral movement. Delivered through multi-stage ClickFix infection chains, the malware features encrypted code blocks, EtherHiding for command-and-control resolution via Polygon JSON-RPC protocol, and multiple anti-analysis techniques including junk code and indirect system calls. SloppyRAT implements certificate pinning to prevent TLS traffic inspection and includes 47 built-in PowerShell-like commands for remote access. The infection chain uses finger.exe, IronPython, and deploys CastleLoader and CastleRAT components before installing SloppyRAT. Despite sophisticated capabilities, the codebase contains numerous software bugs affecting persistence mechanisms and other features, suggesting active development.

Join the discussion

Cisco Talos identified a malware infection chain involving WebDAV-based DLL execution delivering the Amatera stealer and secondary payloads including ZigCryptoStealer and NetSupport Manager. The infection chain uses a Cloudflare Worker to inject JavaScript stored on BNB Smart Chain and a fake CAPTCHA prompt to trick victims into executing the malware. Two distinct DLL loaders named "verification.google" and "pf.ch" were observed, each deploying different secondary payloads. The "verification.google" loader installed NetSupport Manager with a command-and-control server IP linked to Russia, suggesting a Russian threat actor. The infection was first observed in April 2026 targeting a Ukrainian government organization but is assessed as not specifically targeted. Multiple infection chains delivering Amatera stealer have been documented, but no direct infrastructure links were found between them. The threat involves credential and cryptocurrency theft through sophisticated multi-stage delivery mechanisms.

Join the discussion

A resurgence in Node.js abuse has been observed since February 2026, targeting government departments, technology companies, and hotels. Attackers leverage the legitimate, signed node.exe binary to execute malicious JavaScript payloads, evading signature-based detection. In one intrusion at an Asian technology company, attackers downloaded the official Node.js installer after repeated payload blocks and used it to run an implant communicating with Ethereum blockchain gateways via EtherHiding techniques. The same threat actors compromised a U.S. fintech firm, deploying the Rust-based C2Looper backdoor linked to ransomware operations. Multiple attacks involved ModeloRAT, associated with initial access broker Woodgnat, connected to ransomware families including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo. Attackers employ ClickFix techniques for initial access and combine living-off-the-land tools with commodity malware.

Join the discussion

A Magecart campaign uses EtherHiding techniques to perform card-skimming on e-commerce platforms. Attackers compromise legitimate online storefronts, mainly WooCommerce, but also PrestaShop, Magento, and WordPress sites, injecting malicious loaders disguised as Google Tag Manager code. The skimming payloads are staged inside Ethereum blockchain smart-contract storage, making detection more difficult. Over 40 websites across 15 countries have been impacted since April 2026. The infrastructure involves 144 Sepolia contracts controlled by a single wallet, with 20 distinct contracts and skimmer-hosting domains identified. The malicious code appears as normal analytics but steals credit card data from shoppers.

Join the discussion

PavinLoader is a sophisticated multi-stage .NET loader used in various malicious campaigns such as ClickFix attacks, fake software downloads, and malicious RenPy games. It uses heavy obfuscation, abuses legitimate Windows tools like MSBuild, and employs an EtherHiding technique to retrieve command-and-control domains via blockchain. The infection chain includes anti-forensics, anti-analysis, and virtual environment detection stages, ultimately delivering payloads like the Amatera Stealer. The loader demonstrates advanced evasion techniques including custom obfuscation, API hashing, and targeting specific geographic regions. Evidence suggests it may be offered as a Loader-as-a-Service, with over 200 related files sharing common artifacts.

Join the discussion

This threat describes a FakeAgent intrusion campaign discovered through an automated threat hunting agent within ten minutes. The campaign used malvertising on Bing to distribute trojanized Claude Desktop installers hosted on legitimate Anthropic infrastructure. The attack chain involved DLL sideloading via Java Chromium Embedded Framework, tampering with Microsoft Defender, scheduled task persistence disguised as Microsoft Edge updates, and blockchain-based command-and-control infrastructure using EtherHiding techniques. The intrusion deployed SectopRAT malware, which has infostealing and remote desktop capabilities, necessitating full endpoint reimaging and credential resets.

Join the discussion

This macOS malware campaign uses social engineering via fake CAPTCHA pages to trick users into running malicious AppleScript commands. It deploys a persistent backdoor that leverages EtherHiding by storing command-and-control (C2) addresses in Polygon blockchain smart contracts, complicating detection. The malware maintains persistence through LaunchAgents and delivers multiple payloads including the AMOS stealer, which targets cryptocurrency wallets, browser credentials, and macOS Keychain data, as well as the XMRig cryptominer for ongoing revenue. The campaign employs advanced evasion techniques such as character-ID obfuscation and abuse of legitimate macOS utilities. Blockchain transaction analysis reveals the full history of C2 infrastructure rotation and funding, aiding defenders despite the malware's memory-resident nature.

Join the discussion

On August 4, 2026, ChainDrop, a self-propagating worm variant of Mini Shai-Hulud linked to TeamPCP, infiltrated the npm ecosystem through a compromised maintainer account of the keyv ecosystem. The attacker injected malicious code into GitHub repositories, weaponizing legitimate CI/CD pipelines to publish poisoned packages with valid SLSA Build Level 3 provenance attestations, making them indistinguishable from clean releases. ChainDrop spread to over 400 packages within four hours by stealing npm tokens and republishing infected versions. The worm employs Ethereum smart contracts for C2 infrastructure, enabling domain rotation without modifying deployed malware. It features destructive capabilities, wiping victim home directories upon token revocation, and achieves persistence through IDE and AI-agent configuration files. The payload harvests credentials from npm, GitHub, AWS, Azure, GCP, Kubernetes, HashiCorp Vault, and other services, exfiltrating data via GitHub repositories and EtherHiding techniques.

Join the discussion

Showing 1 to 10 of 20 results

Filters:Tag: etherhiding
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses