EtherRAT Techniques Bypass Security Via Ethereum Smart Contracts (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- EtherRAT hides C2 traffic in Ethereum smart contracts using EtherHiding.
- Steals cryptocurrency wallets and login credentials.
- Bypasses network security by mimicking legitimate blockchain traffic.
"EtherRAT, a remote access trojan, employs a technique called EtherHiding to conceal its command-and-control (C2) traffic within Ethereum smart contracts. This allows the malware to evade network security appliances by blending in with legitimate blockchain transactions. The malware specifically targets cryptocurrency wallets and login credentials, posing a significant threat to digital asset security."
no comments yet.