{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/etherhiding/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["macos","command-and-control","blockchain","etherhiding"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe Etherhiding technique represents a sophisticated approach to command and control (C2) where threat actors store malicious payloads, configuration files, or command instructions directly within immutable blockchain transactions. By leveraging public infrastructure - such as Ethereum, Binance Smart Chain, or Polygon - attackers ensure their C2 infrastructure remains highly resilient to traditional sinkholing or takedown efforts. On macOS systems, this manifests as scripting interpreters (e.g., Python, Node.js, zsh) or specific development-oriented applications performing outbound network connections to blockchain API providers like Infura, Alchemy, or public RPC gateways. This activity, observed in campaigns such as SleepyDuck, allows attackers to dynamically reconfigure malware or fetch next-stage payloads by querying specific contract addresses, effectively blending malicious traffic with legitimate Web3 service calls.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial infection via a dropper or malicious document that installs a script or binary on the macOS endpoint.\u003c/li\u003e\n\u003cli\u003eThe malicious process executes via a command interpreter (bash, zsh, python, node) to maintain a low footprint.\u003c/li\u003e\n\u003cli\u003eThe script initiates a network connection to a public blockchain RPC endpoint (e.g., Infura, Alchemy, or a custom drpc.org node).\u003c/li\u003e\n\u003cli\u003eThe script sends an API request to query a specific contract address or transaction history associated with the attacker.\u003c/li\u003e\n\u003cli\u003eThe blockchain returns the encoded malicious configuration or payload URL embedded within the transaction data.\u003c/li\u003e\n\u003cli\u003eThe script decodes the blockchain data and performs a file system modification (e.g., writing a new .js or .py file) to persist the retrieved instructions.\u003c/li\u003e\n\u003cli\u003eThe malware executes the newly written configuration or payload to carry out final objectives, such as exfiltration or further system compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful implementation of Etherhiding allows attackers to bypass traditional domain-based C2 blocking, leading to persistent, long-term unauthorized access. This technique increases the difficulty of incident response, as the primary C2 channel is hosted on globally distributed, immutable blockchain infrastructure. Organizations may suffer from extended dwell time, covert data exfiltration, or secondary malware deployment, particularly in environments where Web3 development tools or cryptocurrency applications are common, making detection noise-heavy.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eDeploy the provided detection logic to monitor for suspicious network connections from scripting interpreters to known blockchain RPC providers.\u003c/li\u003e\n\u003cli\u003eAudit endpoints for the use of cryptocurrency-related tools and determine if these are sanctioned business applications.\u003c/li\u003e\n\u003cli\u003eImplement egress filtering at the network perimeter to restrict traffic to known-bad or unnecessary public blockchain API endpoints.\u003c/li\u003e\n\u003cli\u003eMonitor file system modifications in sensitive directories that align with network connections from scripting interpreters.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-08T13:32:23Z","date_published":"2026-09-08T13:32:23Z","id":"https://feed.craftedsignal.io/briefs/2026-09-etherhiding-c2/","summary":"Adversaries are utilizing blockchain RPC endpoints as a resilient, censorship-resistant covert channel to retrieve configuration data and commands for macOS malware.","title":"Potential Etherhiding Command and Control via Blockchain Infrastructure","url":"https://feed.craftedsignal.io/briefs/2026-09-etherhiding-c2/"}],"language":"en","title":"CraftedSignal Threat Feed - Etherhiding","version":"https://jsonfeed.org/version/1.1"}