Potential Etherhiding C2 Via Blockchain Connection
Detects when a scripting interpreter makes an outbound network connection to an Ethereum blockchain endpoint for command and control purposes. Adversaries may leverage Ethereum blockchain infrastructure as a covert C2 channel to receive commands and exfiltrate data, as observed in campaigns like SleepyDuck malware.
Searches indices from : now-9m ( Date Math format , see also Additional look-back time )
Maximum alerts per execution : 100
Rule license : Elastic License v2
Disclaimer : This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs.
Investigating Potential Etherhiding C2 via Blockchain Connection
Etherhiding is an advanced command and control technique where threat actors store malicious configurations, commands, or payload URLs within blockchain transactions on platforms like Ethereum or Binance Smart Chain. This approach provides a highly resilient and censorship-resistant C2 infrastructure since blockchain data cannot be taken down or modified. This detection rule identifies script interpreters or suspicious processes connecting to blockchain API endpoints that may be retrieving attacker-controlled data from the blockchain.
Possible investigation steps
False positive analysis
Response and remediation
Framework : MITRE ATT&CK TM
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
