Cribl Uncovers EtherHiding ClickFix Campaign
Cribl discovered a ClickFix campaign using EtherHiding with the Polygon blockchain to hide C2 domains in smart contracts.
Cribl discovered a ClickFix campaign using EtherHiding with the Polygon blockchain to hide C2 domains in smart contracts.
This week's ThreatsDay Bulletin covers a wide range of cybersecurity developments, including new attack techniques, data breaches, and product updates. Key highlights…
Cybersecurity researchers have uncovered a new evolution of the EtherHiding blockchain-based command-and-control (C2) technique, dubbed NullReceiver, which conceals the C2 server IP…
EtherHiding is a covert technique that embeds malicious code within smart contracts on public blockchains like BNB Smart Chain or Ethereum. It…
A new Russian loader-as-a-service (LaaS) operation named DOUBLECUP is leveraging ClickFix social engineering lures and steganographic PNG images cached in victims' browsers…
DeviceManager is a modular Python-based remote access trojan distributed via DOUBLECUP. It uses EtherHiding to resolve C2 servers via Ethereum/Polygon smart contracts…
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake…
Guardio Labs is a cybersecurity company that first publicly documented the EtherHiding technique in October 2023. Their research highlighted how attackers embed…
Russian state-sponsored threat actors from the UAC-0145 sub-cluster, linked to Sandworm and GRU, are using fake CAPTCHA checks on compromised websites to…
Ethereum is a blockchain platform used in the EtherHiding technique to retrieve domain names from smart contracts for malicious CAPTCHA injection.