EXECUTIVE SUMMARY
A recently discovered C++ botnet loader shifts its command-and-control infrastructure entirely to the public Polygon blockchain, operated by threat actors who write encrypted and plaintext instructions directly using smart contracts. The goal of this attack is data theft and disruption, primarily targeting devices in various sectors and regions. The attackers use this malware to operate a resilient and low-cost threat that complicates existing law enforcement takedown methods.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A recently discovered C++ botnet loader shifts its command-and-control infrastructure entirely to the public Polygon blockchain, operated by threat actors who write encrypted and plaintext instructions directly using smart contracts. The goal of this attack is data theft and disruption, primarily targeting devices in various sectors and regions. The attackers use this malware to operate a resilient and low-cost threat that complicates existing law enforcement takedown methods.[emaillocker id="1283"]
The malware infects systems by querying public remote procedure call endpoints to retrieve and execute on-chain commands, allowing the attacker to maintain control. Once inside, the malware performs various activities, including reconnaissance, decryption of encrypted commands, and data exfiltration. The malware also downloads files from GitHub repositories and interacts with social media platforms like Telegram for command and control communications.
The attacker uses decentralized networks and evasion techniques, such as virtual machine detection and antivirus scanning, to operate effectively. This threat is significant for organisations because it establishes a highly resilient and low-cost threat that is difficult to detect and recover from. Organisations should take defensive actions, such as patching, monitoring, backups, and endpoint protection, to protect themselves from this threat. The use of blockchain-based command and control infrastructure makes it challenging for organisations to detect and respond to this threat, highlighting the need for advanced security measures and threat intelligence to stay ahead of such threats.
THREAT PROFILE:
| Tactic | Technique ID | Technique | Sub-technique |
| Persistence | T1547.009 | Boot or Logon Autostart Execution | Shortcut Modification |
| Defense Evasion | T1027.002 | Obfuscated Files or Information | Software Packing |
| Defense Evasion | T1497.001 | Virtualization/Sandbox Evasion | System Checks |
| Discovery | T1082 | System Information Discovery | — |
| Command and Control | T1071.001 | Application Layer Protocol | Web Protocols |
| Command and Control | T1105 | Ingress Tool Transfer | — |
REFERENCES:
The reports contain further technical details:
https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/