A recent investigation into a state-linked intrusion set uncovered a command-and-control (C2) infrastructure that leveraged a public blockchain to resolve its C2 address, with the malware reading a smart contract to obtain the necessary information1. Further analysis revealed that the initial contract identified was part of a larger family, comprising over two dozen byte-identical contracts and variants, all emitting the same event and created by the same builder. Approximately 30 operator wallets were linked to this C2 kit, which was used by at least two governments. The use of a public blockchain to facilitate C2 communications adds a new layer of complexity to the threat landscape. This discovery highlights the adaptability of threat actors in utilizing emerging technologies to support their operations, making it essential for security practitioners to stay informed about the evolving tactics and techniques used by these groups.
One C2 kit. 30 customers. 2 governments
⚡ High Priority
Why This Matters
The malware resolved its C2 address by reading a smart contract on a public blockchain.
References
- CSO Online. (2026, August 5). One C2 kit. 30 customers. 2 governments. *CSO Online*. https://www.csoonline.com/article/4205129/one-c2-kit-30-customers-2-governments.html
Original Source
CSO Online
Read original →