This week's ThreatsDay Bulletin covers a wide range of cybersecurity developments, including new attack techniques, data breaches, and product updates. Key highlights…
Cybersecurity researchers have uncovered a new evolution of the EtherHiding blockchain-based command-and-control (C2) technique, dubbed NullReceiver, which conceals the C2 server IP…
Six npm packages use the NullReceiver technique, fetching next-stage payloads via Ethereum transactions linked to North Korean threat actors, evolving from EtherHiding.
Russian state-sponsored threat actors from the UAC-0145 sub-cluster, linked to Sandworm and GRU, are using fake CAPTCHA checks on compromised websites to…
Ethereum is a blockchain platform used in the EtherHiding technique of the DPRK malvertising campaign. Malware extracts C2 server addresses from Ethereum…