⤷ Title: ClearFake Malware Variant Exploits Web3 in New Attacks
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Thu, 20 Mar 2025 01:55:30 +0000
════════════════════════
⌗ Tags: #Malware #Binance Smart Chain #ClearFake #ClearFake malware #ClickFix #Cloudflare Turnstile #Emmenhtal Loader #EtherHiding #Lumma Stealer #powershell #reCAPTCHA #Web3
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Thu, 20 Mar 2025 01:55:30 +0000
════════════════════════
⌗ Tags: #Malware #Binance Smart Chain #ClearFake #ClearFake malware #ClickFix #Cloudflare Turnstile #Emmenhtal Loader #EtherHiding #Lumma Stealer #powershell #reCAPTCHA #Web3
Daily CyberSecurity
ClearFake Malware Variant Exploits Web3 in New Attacks
Uncover the latest variant of ClearFake malware, EtherHiding, exploiting Web3 features for advanced malicious tactics.
⤷ Title: UNC5142 Uses EtherHiding to Deploy Malware via BNB Smart Chain Smart Contracts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:32:34 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #Blockchain #BNB Smart Chain #C2 #Decentralization #EtherHiding #Malware Distribution #Smart Contract #UNC5142
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:32:34 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #Blockchain #BNB Smart Chain #C2 #Decentralization #EtherHiding #Malware Distribution #Smart Contract #UNC5142
Daily CyberSecurity
UNC5142 Uses EtherHiding to Deploy Malware via BNB Smart Chain Smart Contracts
Mandiant exposed UNC5142 for using EtherHiding—hiding malicious JavaScript in BNB Smart Chain smart contracts—to create a resilient C2 and distribute VIDAR/ATOMIC to 14,000+ sites.
⤷ Title: North Korea’s UNC5342 APT Uses EtherHiding to Store Malware in Blockchain Smart Contracts for Stealthy C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:10:31 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Blockchain #C2 #Crypto theft #EtherHiding #InvisibleFerret #North Korea APT #Smart Contract #UNC5342
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 00:10:31 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Blockchain #C2 #Crypto theft #EtherHiding #InvisibleFerret #North Korea APT #Smart Contract #UNC5342
Daily CyberSecurity
North Korea's UNC5342 APT Uses EtherHiding to Store Malware in Blockchain Smart Contracts for Stealthy C2
Google exposed UNC5342 (DPRK APT) using EtherHiding—hiding JADESNOW/INVISIBLEFERRET malware in BNB/Ethereum smart contracts—for a resilient, nation-state C2 infrastructure.
⤷ Title: North Korean Hackers Adopt “EtherHiding” to Conceal Malware in Smart Contracts
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 21 Oct 2025 03:55:30 +0000
════════════════════════
⌗ Tags: #Cyber Security #blockchain #cybersecurity #EtherHiding #malware #North Korea
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 21 Oct 2025 03:55:30 +0000
════════════════════════
⌗ Tags: #Cyber Security #blockchain #cybersecurity #EtherHiding #malware #North Korea
Penetration Testing Tools
North Korean Hackers Adopt "EtherHiding" to Conceal Malware in Smart Contracts
A North Korean-linked group is using "EtherHiding" to hide malware payloads inside smart contracts, creating a decentralized, untraceable C2 infrastructure.
⤷ Title: Implementing the Etherhiding technique
════════════════════════
𐀪 Author: Onhexgroup
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 18:54:11 GMT
════════════════════════
⌗ Tags: #etherhiding #smart_contracts #cybersecurity #infosec #solidity
════════════════════════
𐀪 Author: Onhexgroup
════════════════════════
ⴵ Time: Wed, 29 Oct 2025 18:54:11 GMT
════════════════════════
⌗ Tags: #etherhiding #smart_contracts #cybersecurity #infosec #solidity
Medium
Implementing the Etherhiding technique
Google recently published reports about a new technique called “Etherhiding.” The reports explain how the threat actors UNC5142 and UNC5342…
⤷ Title: EtherRAT Malware Hijacks Ethereum Blockchain for Covert C2 After React2Shell Exploit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 09:10:41 +0000
════════════════════════
⌗ Tags: #Malware #APT #Blockchain C2 #CVE_2025_55182 #Ethereum #EtherHiding #EtherRAT #North Korea #rce #React2Shell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Dec 2025 09:10:41 +0000
════════════════════════
⌗ Tags: #Malware #APT #Blockchain C2 #CVE_2025_55182 #Ethereum #EtherHiding #EtherRAT #North Korea #rce #React2Shell
Daily CyberSecurity
EtherRAT Malware Hijacks Ethereum Blockchain for Covert C2 After React2Shell Exploit
A sophisticated new malware, EtherRAT, leverages Ethereum smart contracts for covert C2 (EtherHiding) 48 hours after the React2Shell (CVSS 10.0) flaw. Analysis shows ties to North Korean APTs.
⤷ Title: Taming the Wolf: How the 1.8 Million-Strong Kimwolf Botnet Overtook Google Traffic
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 02:47:16 +0000
════════════════════════
⌗ Tags: #Malware #AISURU #Android TV #BOTNET #DDoS #ENS #EtherHiding #IoT Security #Kimwolf #Proxy_as_a_Service #QiAnXin XLab #Smart Home Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 02:47:16 +0000
════════════════════════
⌗ Tags: #Malware #AISURU #Android TV #BOTNET #DDoS #ENS #EtherHiding #IoT Security #Kimwolf #Proxy_as_a_Service #QiAnXin XLab #Smart Home Security
Penetration Testing Tools
Taming the Wolf: How the 1.8 Million-Strong Kimwolf Botnet Overtook Google Traffic
The Kimwolf botnet has drawn intense scrutiny after researchers at QiAnXin XLab reported that it had infected more
⤷ Title: The Blockchain Ghost: DeadLock Ransomware Uses Smart Contracts to Defy Bans
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 16 Jan 2026 03:26:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BYOVD #Cisco Talos #Cyber Security 2026 #DeadLock #EtherHiding #Group_IB #Infosec News #Polygon Blockchain #ransomware #Session App #smart contracts
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 16 Jan 2026 03:26:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BYOVD #Cisco Talos #Cyber Security 2026 #DeadLock #EtherHiding #Group_IB #Infosec News #Polygon Blockchain #ransomware #Session App #smart contracts
Penetration Testing Tools
The Blockchain Ghost: DeadLock Ransomware Uses Smart Contracts to Defy Bans
The DeadLock syndicate, which emerged within the cyber threat landscape during the summer of 2025, persists as one
⤷ Title: DeadLock Ransomware: New Strain Hides C2 in Polygon Smart Contracts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 16 Jan 2026 02:10:20 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Blockchain security #C2 Infrastructure #Cyber Security #DeadLock #EtherHiding #Group_IB #Polygon Network #ransomware #Session Messenger #smart contracts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 16 Jan 2026 02:10:20 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Blockchain security #C2 Infrastructure #Cyber Security #DeadLock #EtherHiding #Group_IB #Polygon Network #ransomware #Session Messenger #smart contracts
Daily CyberSecurity
DeadLock Ransomware: New Strain Hides C2 in Polygon Smart Contracts
A new ransomware family is turning the decentralized dream of blockchain into a cybersecurity nightmare. Analysts at Group-IB have uncovered DeadLock, a ransomware strain discovered in July 2025 t…
⤷ Title: OCRFix: When Fake CAPTCHAs, AI, and Blockchains Collide to Build a Botnet
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Mar 2026 00:27:28 +0000
════════════════════════
⌗ Tags: #Malware #AI SEO Poisoning #BNB Smart Chain #botnet #ClickFix #CYJAX #EtherHiding #infosec #OCRFix #PowerShell Malware #social engineering #Tesseract OCR
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Mar 2026 00:27:28 +0000
════════════════════════
⌗ Tags: #Malware #AI SEO Poisoning #BNB Smart Chain #botnet #ClickFix #CYJAX #EtherHiding #infosec #OCRFix #PowerShell Malware #social engineering #Tesseract OCR
Daily CyberSecurity
OCRFix: When Fake CAPTCHAs, AI, and Blockchains Collide to Build a Botnet
CYJAX uncovers "OCRFix," a stealthy campaign using fake Tesseract OCR sites, ClickFix social engineering, and EtherHiding to bypass security via blockchain.
⤷ Title: Unmasking OCRFix: The New Russian Botnet Hiding its C2 Infrastructure in the Blockchain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Mar 2026 00:07:58 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain security #ClickFix #cybersecurity #EtherHiding #infosec #OCRFix Botnet #Russian Malware #smart contracts #threat intelligence #VBScript Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Mar 2026 00:07:58 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain security #ClickFix #cybersecurity #EtherHiding #infosec #OCRFix Botnet #Russian Malware #smart contracts #threat intelligence #VBScript Malware
Daily CyberSecurity
Unmasking OCRFix: The New Russian Botnet Hiding its C2 Infrastructure in the Blockchain
Cybersecurity researchers uncover OCRFix, a Russian-linked botnet using EtherHiding and fake CAPTCHAs to mask its C2 servers in blockchain smart contracts.