Tag
MovieReaper Multi-Stage Trojan Campaign
1 rule 3 TTPs 4 IOCsMovieReaper is a multi-stage modular Trojan distributed via compromised torrent files on itorrents.org that leverages the Solana blockchain for C2 discovery and achieves persistence via UAC bypass.
Potential Etherhiding Command and Control via Blockchain Infrastructure
1 rule 2 TTPsAdversaries are utilizing blockchain RPC endpoints as a resilient, censorship-resistant covert channel to retrieve configuration data and commands for macOS malware.
Integer Overflow in Klever Split-Royalty Validation Enables Unbounded Token Minting
1 TTPAn integer overflow vulnerability in the Klever node (klever-go) allows attackers to mint arbitrary amounts of KLV and other assets by bypassing split-royalty validation checks.
DeadLock Ransomware Leverages Polygon Smart Contracts for Resilient C2
1 rule 3 TTPs 1 IOCThe DeadLock ransomware group employs decentralized infrastructure, including Polygon smart contracts, to rotate proxy servers and host data leak blogs, complicating traditional takedown efforts.
Aeternum Botnet Leverages Polygon Blockchain for Decentralized C2
1 rule 3 TTPs 3 IOCsAeternum is a C++ botnet loader that utilizes Polygon blockchain smart contracts for resilient, decentralized command-and-control communication and payload delivery.
Zebra Block Suppression Vulnerability (CVE-2026-52736) via P2P Body Poisoning
2 TTPsA remote unauthenticated attacker can exploit CVE-2026-52736 in Zebra's `zebrad` node (versions up to and including `v4.4.1`) to permanently stall a targeted blockchain node by poisoning its sent-hash cache, leading to a denial of service.
Zebra Block Validator Sigops Undercount Vulnerability
2 rulesZebra's block validator undercounts signature operations, allowing it to accept invalid blocks, leading to a network split between Zebra and zcashd nodes.
Mezo L1 Bridge Vulnerability Leads to Potential ERC-20 Drain
3 rules 2 TTPsA vulnerability in the Mezo bridge allows for the potential full drain of the L1 bridge without changing the bridged balance on Mezo due to a stale StateDB overwrite, enabling a malicious user to steal ERC-20 tokens locked in the L1 bridge.
Nimiq Blockchain Timestamp Manipulation Vulnerability
2 rules 4 TTPs 1 CVEA vulnerability in nimiq-blockchain versions 1.3.0 and earlier allows malicious validators to manipulate block timestamps, leading to inflation of the monetary supply.
BSV Ruby SDK Improper ARC Response Handling
2 rules 1 TTP 1 CVEBSV Ruby SDK versions before 0.8.2 improperly handle ARC responses, treating certain failure statuses as successful broadcasts, potentially tricking applications into trusting unaccepted transactions; version 0.8.2 resolves this vulnerability.
Zebra Consensus Split Vulnerability Due to SIGHASH_SINGLE Handling
2 rulesZebra and zcashd disagree on a consensus rule for V5+ transparent spends related to SIGHASH_SINGLE handling when the input index has no corresponding output, leading to a consensus split where Zebra accepts invalid blocks rejected by zcashd.
Nimiq Block Skip Block Quorum Bypass Vulnerability
2 rules 1 TTPA vulnerability exists in Nimiq Block's SkipBlockProof verification process, allowing attackers to bypass quorum checks by manipulating MultiSignature signers with out-of-range indices, potentially compromising blockchain integrity, and affecting rust/nimiq-block versions 0.2.0 and earlier.