The Unkillable C2: How Attackers Are Moving Command and Control to the Blockchain
Blog post from Endor Labs
Malware's evolution from traditional Command and Control (C2) servers to blockchain-based C2 infrastructures marks a significant shift in cybersecurity, presenting new challenges for defenders. Traditionally, C2 servers have been vulnerable as single points of failure that could be seized or shut down, disrupting malware operations. However, with the advent of blockchain technology, attackers have begun utilizing its distributed, immutable, and publicly readable nature to create resilient malware infrastructures that cannot be easily dismantled. Techniques such as EtherHiding allow attackers to use smart contracts on blockchains like BNB Smart Chain to dynamically update malicious payload addresses, circumventing traditional takedown methods. This trend is further exemplified by developments like the Aeternum C2 botnet, which commoditizes blockchain-based malware operations, making sophisticated attacks accessible to less skilled actors. Consequently, defenders face a complex task as traditional infrastructure takedown strategies become less effective. Instead, they must focus on monitoring for anomalous blockchain interactions, leveraging blockchain intelligence, and reinforcing other segments of the attack chain, such as initial compromises and endpoint defenses, to mitigate these advanced threats.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.