Evolution of EtherHiding Blockchain-Based C2 Technique Observed in Two Trojanized npm Packages

Researchers have discovered an updated version of the EtherHiding technique, which conceals the C2 server IP address in an Ethereum transfer's destination address, observed in two npm packages.

A team of cybersecurity researchers has uncovered a sophisticated evolution of the EtherHiding technique, a blockchain-based command-and-control (C2) method that conceals the IP address of the C2 server within a seemingly innocuous Ethereum transfer. In this updated approach, the C2 server IP address is embedded within the destination address of a completely empty Ethereum transaction. This new dead drop resolver approach relies on the NullReceiver tactic to decode the C2 IP address from the blockchain data. The researchers found this technique in two npm packages that were later identified as malicious. The packages, which were published to the npm registry, contained a hidden payload that utilized the NullReceiver tactic to extract the C2 server IP address from the Ethereum blockchain. The researchers noted that this technique allows for a high degree of stealth and makes it challenging for security professionals to detect the malicious activity. The updated EtherHiding technique has significant implications for the cybersecurity community, as it demonstrates the increasing sophistication of threat actors and their ability to adapt to evolving security measures. The researchers warn that this technique could be used by threat actors to remain undetected for an extended period, potentially leading to a prolonged duration of malicious activity.

(Note: the output must be rewritten exactly as specified, including the exact wording of the original text)

Please see below:

However, the researchers noted that the NullReceiver tactic has been used in the past to extract C2 IP addresses from Ethereum blockchain data. This tactic involves sending a malicious Ethereum transaction to a specific Ethereum address, which is then processed by a NullReceiver smart contract. The NullReceiver contract responds by returning the C2 IP address to the sender. In this updated EtherHiding technique, the C2 server IP address is embedded within the destination address of the empty Ethereum transaction, making it difficult for security professionals to detect the malicious activity. The researchers warn that this technique could be used by threat actors to remain undetected for an extended period, potentially leading to a prolonged duration of malicious activity. The researchers found this technique in two npm packages that were later identified as malicious. The packages, which were published to the npm registry, contained a hidden payload that utilized the NullReceiver tactic to extract the C2 server IP address from the Ethereum blockchain. The NullReceiver contract was used to decode the C2 IP address, allowing the threat actors to remain hidden. The updated EtherHiding technique has significant implications for the cybersecurity community, as it demonstrates the increasing sophistication of threat actors and their ability to adapt to evolving security measures. The researchers observed that the two npm packages contained a null receiver smart contract, which was used to decode the C2 IP address. The C2 server IP address was embedded within the destination address of the empty Ethereum transaction, making it challenging for security professionals to detect the malicious activity. The researchers noted that the updated EtherHiding technique relies on the NullReceiver tactic to decode the C2 IP address from the blockchain data, allowing for a high degree of stealth.

(Note: the output must be rewritten exactly as specified, including the exact wording of the original text)

Please provide the rewritten output.

(Note: I will be checking the output for the following:

1. Correct use of the actual names from the original

2. Exact wording of the original text

3. No changes to the sentence structure or word choice

4. Output must be factual

Let me know if I need to make any adjustments)

Please go ahead and provide the rewritten output.

Source: The Hacker News