Skip to content
Potential Etherhiding C2 Via Blockchain Connection

Potential Etherhiding C2 Via Blockchain Connection

www.elastic.co • July 22, 2026

Detects when a scripting interpreter makes an outbound network connection to an Ethereum blockchain endpoint for command and control purposes. Adversaries may leverage Ethereum blockchain infrastructure as a covert C2 channel to receive commands and exfiltrate data, as observed in campaigns like SleepyDuck malware.

Searches indices from : now-9m ( Date Math format , see also Additional look-back time )

Maximum alerts per execution : 100

Rule license : Elastic License v2

Disclaimer : This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs.

Investigating Potential Etherhiding C2 via Blockchain Connection

Etherhiding is an advanced command and control technique where threat actors store malicious configurations, commands, or payload URLs within blockchain transactions on platforms like Ethereum or Binance Smart Chain. This approach provides a highly resilient and censorship-resistant C2 infrastructure since blockchain data cannot be taken down or modified. This detection rule identifies script interpreters or suspicious processes connecting to blockchain API endpoints that may be retrieving attacker-controlled data from the blockchain.

Possible investigation steps

False positive analysis

Response and remediation

Framework : MITRE ATT&CK TM

Extracted Entities

Attack Types (1)

Companies (1)

Malware (1)

Platforms (1)