lists.ifin.network
RPC Nodes - IFIN Lists
A curated collection of long-term block lists and hunting targets for all organizations, along with documentation and explanations.
#EtherHiding is an active hashtag on Bluesky. In the last 30 days, 8 people shared 16 posts with it — around 1 a day. Activity is up 0% versus the previous week, peaking on Aug 31 with 2 posts.
lists.ifin.network
RPC Nodes - IFIN Lists
A curated collection of long-term block lists and hunting targets for all organizations, along with documentation and explanations.
www.chainalysis.com
DPRK and Iran are Leading a 5.2x Surge YoY in Blockchain-Assisted Cyberattacks
blog.sekoia.io
ClearFake’s New Widespread Variant: Increased Web3 Exploitation for Malware Delivery
ClearFake spreads malware via compromised websites, using fake CAPTCHAs, JavaScript injections, and drive-by downloads.
socket.dev
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
www.netskope.com
Malware on the Blockchain: An Ongoing Campaign's New WebRTC Twist
EtherHiding, a technique that uses blockchain smart contracts as takedown-resistant payload storage, has been seen across more than 5,400 compromised
www.allsecure.io
ClickFix, EtherHiding & a DPRK Wallet Trail
securityonline.info
Node.js Backdoor Hides Its C2 on the TON Blockchain
At a glance Malware family Node.js backdoor (tracked as "TonRAT" by some researchers) Threat actor Unattributed; no named group Target / victims Hospitality sector; hotel staff Delivery vector Booking-themed phishing email to a ZIP with a malicious LNK Key capabilities Remote code execution, payload download, persistence, blockchain-based C2 Source LevelBlue Managed Threat Research TL;DR LevelBlue has detailed a phishing campaign that drops a Node.js…
www.hendryadrian.com
SloppyRAT: A New Tool For Ransomware Attacks
Zscaler ThreatLabz identified SloppyRAT, a new malware family likely used in ransomware-related attacks and delivered through a multi-stage ClickFix infection chain. It combines anti-analysis features, EtherHiding-based C2 resolution, certificate pinning, and extensive remote command execution capabilities, while also showing signs of ongoing development and coding flaws. #SloppyRAT #ClickFix #CastleLoader #CastleRAT #EtherHiding
socket.dev
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
www.chainalysis.com
DPRK and Iran are Leading a 5.2x Surge YoY in Blockchain-Assisted Cyberattacks
lists.ifin.network
RPC Nodes - IFIN Lists
A curated collection of long-term block lists and hunting targets for all organizations, along with documentation and explanations.
www.hendryadrian.com
SloppyRAT: A New Tool For Ransomware Attacks
Zscaler ThreatLabz identified SloppyRAT, a new malware family likely used in ransomware-related attacks and delivered through a multi-stage ClickFix infection chain. It combines anti-analysis features, EtherHiding-based C2 resolution, certificate pinning, and extensive remote command execution capabilities, while also showing signs of ongoing development and coding flaws. #SloppyRAT #ClickFix #CastleLoader #CastleRAT #EtherHiding
securityonline.info
Node.js Malware Attacks Target Tech and Finance Sectors
At a Glance Malware family: Multiple families including ModeloRAT, EtherRAT, AsukaStealer, and C2Looper Threat actor: Suspected initial access broker Woodgnat (KongTuke) and unnamed cybercrime groups Target or victims: Technology firms, fintech companies, hotels, and government agencies Delivery vector: ClickFix fake update prompts and malicious PowerShell commands Key capabilities: Living-off-the-land execution, registry persistence, and blockchain-based EtherHiding Source: Symantec Threat Hunter Team and Zscaler…
cyberveille.ch
EtherHiding + WebRTC : campagne malveillante via blockchain BSC testnet sur 5 400 sites
Cet article présente l'analyse technique d'une campagne malveillante en cours exploitant la technique EtherHiding — l'utilisation de smart contracts blockchain comme stockage de payload résistant aux takedowns.
www.hendryadrian.com
Over 5,400 Hacked Sites Serve ClickFix Payloads Stored On The Blockchain
A large criminal campaign is using more than 5,400 compromised WordPress and PrestaShop websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain via EtherHiding. The operation has evolved to use a WebRTC-based stager and is contacting BSC Testnet RPC endpoints at scale, making the infrastructure harder to disrupt. #BNBSmartChain #EtherHiding #ClickFix #WordPress #PrestaShop
www.netskope.com
Malware on the Blockchain: An Ongoing Campaign's New WebRTC Twist
EtherHiding, a technique that uses blockchain smart contracts as takedown-resistant payload storage, has been seen across more than 5,400 compromised
securityonline.info
Amatera Password Stealer Abuses Service Workers and Smart Contracts
At a Glance Category Details Malware Family Amatera (rebrand of ACR Stealer / AcridRain) Threat Actor Unattributed (overlaps with ErrTraffic Malware-as-a-Service ecosystem) Target or Victims Visitors of hundreds of compromised WordPress websites Delivery Vector Rogue WordPress plugin, browser Service Worker, fake reCAPTCHA ClickFix lure Key Capabilities Browser persistence, CSP stripping, EtherHiding blockchain resolution, credential theft Source Netskope Threat Labs TL;DR…
Posts are pulled live from Bluesky and cached briefly. Posts with content labels are hidden.