Polygon: EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials

Polygon: EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials

EtherHiding Campaign Leverages Polygon Blockchain for Resilient C2 Infrastructure

A newly identified EtherHiding campaign has exploited the Polygon blockchain to create a highly resilient command-and-control (C2) mechanism, enabling attackers to rotate malware infrastructure without altering payloads on compromised systems. Active since at least November 2025, the operation has breached 31 legitimate business websites, evolving from a general-purpose PowerShell backdoor to a real-time banking trojan targeting 479 financial and cryptocurrency domains.

Unlike traditional malware, the implant avoids hardcoded C2 addresses. Instead, it queries a hardcoded Polygon smart contract via public RPC endpoints, decrypting the C2 domain at runtime. This EtherHiding technique transforms the blockchain into a dynamically updateable, attacker-controlled address book. By leveraging Polygon’s decentralized nature, the threat actors evade conventional takedowns defenders cannot simply block or seize domains through registrars or hosting providers.

The attack chain begins on compromised websites, often accessed via Bing or Google search results. Malicious JavaScript injects a FakeCaptcha or ClickFix overlay, tricking users into executing a supplied command via Windows+R. This triggers a Windows Scheduled Task ("Enter") that repeatedly attempts payload delivery. Once executed, the malware deploys paired PowerShell scripts in the user’s Temp directory one for reboot persistence (via the Registry) and another as the core C2 agent. The scheduled task is then removed to reduce detection.

GuidePoint Security’s DFIR team uncovered the campaign during a business email compromise (BEC) investigation, identifying a Polygon smart contract embedded in the malware’s execution chain. The backdoor queries Polygon RPC endpoints, retrieves an encrypted C2 domain from the contract, and initiates communications using a custom XOR cipher, embedding beacon data in the HTTP Authorization header. The malware also generates a victim identifier from the Windows MachineGuid, hostname, and username, enabling remote PowerShell execution via new processes or Invoke-Expression.

Blockchain analysis revealed 15 smart contracts deployed in six operational waves over seven months, controlled through two wallets. Early contracts emitted on-chain events when C2 values changed, allowing researchers to trace infrastructure rotations. Later contracts were silent, suggesting the operators adapted to evade event-based detection. Active C2 domains include hivinest[.]online, insinght[.]site, and 3262d48df5d75e34[.]shop, with a fourth domain (ddcd62e16a428c8e[.]shop) suspended by its registrar. The attackers maintain multiple parallel C2 domains, limiting the effectiveness of single-domain blocklists.

The campaign’s sophistication escalated with the introduction of a fake browser extension capable of intercepting credentials and two-factor authentication codes in real time, shifting the threat from generic remote access to direct financial theft and account takeover. Defenders are advised to monitor for unexpected Polygon RPC connections, particularly from endpoints without legitimate blockchain use, as well as suspicious activity such as the "Enter" scheduled task, PowerShell operations in Temp directories, and modifications to the PersonalizedUpdates Run key.

While EtherHiding complicates traditional C2 disruption, it leaves an immutable on-chain trail. Every contract deployment and update is permanently recorded, enabling defenders to map wallets, infrastructure rotations, and campaign timelines long after domains are rotated. The incident underscores the growing use of blockchain-based C2 mechanisms to evade detection and maintain persistence.

Source: https://gbhackers.com/etherhiding-malware-attack/

Polygon Labs cybersecurity rating report: https://www.rankiteo.com/company/polygonlabs

"id": "POL1789971919",
"linkid": "polygonlabs",
"type": "Cyber Attack",
"date": "11/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': ['Financial', 'Cryptocurrency'],
                        'type': 'Business websites'}],
 'attack_vector': ['Compromised websites',
                   'Malicious JavaScript injection (FakeCaptcha/ClickFix)',
                   'Windows Scheduled Task'],
 'data_breach': {'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Credentials',
                                              'Two-factor authentication '
                                              'codes']},
 'date_detected': '2025-11',
 'description': 'A newly identified EtherHiding campaign has exploited the '
                'Polygon blockchain to create a highly resilient '
                'command-and-control (C2) mechanism, enabling attackers to '
                'rotate malware infrastructure without altering payloads on '
                'compromised systems. The operation has breached 31 legitimate '
                'business websites, evolving from a general-purpose PowerShell '
                'backdoor to a real-time banking trojan targeting 479 '
                'financial and cryptocurrency domains.',
 'impact': {'data_compromised': ['Credentials',
                                 'Two-factor authentication codes'],
            'identity_theft_risk': 'High',
            'payment_information_risk': 'High',
            'systems_affected': ['31 legitimate business websites',
                                 'End-user systems via malware execution']},
 'initial_access_broker': {'backdoors_established': ['PowerShell backdoor',
                                                     'Fake browser extension'],
                           'entry_point': 'Compromised websites via '
                                          'Bing/Google search results',
                           'high_value_targets': ['Financial domains',
                                                  'Cryptocurrency domains']},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'The incident underscores the growing use of '
                    'blockchain-based C2 mechanisms to evade detection and '
                    'maintain persistence, leaving an immutable on-chain trail '
                    'for defenders to map infrastructure rotations and '
                    'campaign timelines.',
 'motivation': ['Financial theft', 'Account takeover'],
 'post_incident_analysis': {'root_causes': ['Exploitation of Polygon '
                                            'blockchain for resilient C2 '
                                            'infrastructure',
                                            'Malicious JavaScript injection '
                                            'leading to malware execution']},
 'recommendations': ['Monitor for unexpected Polygon RPC connections, '
                     'particularly from endpoints without legitimate '
                     'blockchain use.',
                     "Detect suspicious activity such as the 'Enter' scheduled "
                     'task, PowerShell operations in Temp directories, and '
                     'modifications to the PersonalizedUpdates Run key.'],
 'references': [{'source': 'GuidePoint Security’s DFIR team'}],
 'response': {'enhanced_monitoring': ['Monitor for unexpected Polygon RPC '
                                      'connections',
                                      'Suspicious PowerShell operations in '
                                      'Temp directories'],
              'third_party_assistance': 'GuidePoint Security’s DFIR team'},
 'title': 'EtherHiding Campaign Leverages Polygon Blockchain for Resilient C2 '
          'Infrastructure',
 'type': ['Malware', 'Banking Trojan', 'Command-and-Control (C2)']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.