EtherHiding is a blockchain-based command-and-control concealment and configuration retrieval technique used by malware to obtain live infrastructure or payload data from public blockchain platforms instead of relying on fixed traditional servers. Implementations commonly query smart contracts or transaction data on networks such as Ethereum, Polygon, BNB Smart Chain, and Avalanche, then decode attacker-controlled configuration such as next-stage endpoints or tasking. This design gives operators resilient, easily rotated infrastructure and complicates takedown and static detection because the malware can resolve updated command data at runtime from decentralized services.
EtherHiding has been observed across multiple malware delivery ecosystems and intrusion sets, including campaigns linked to DPRK-associated activity such as Contagious Interview and UNC5342 tradecraft. It has appeared in software supply-chain compromises affecting npm packages and developer tooling, ClickFix and fake-update style social-engineering chains, trojanized GitHub repositories, malicious browser-extension campaigns, WordPress-based traffic distribution systems, and macOS and Windows malware loaders. Reported payloads and follow-on malware using EtherHiding include remote access trojans, infostealers, crypto-theft malware, browser-extension malware, and multi-stage loaders.
Operationally, malware using EtherHiding typically performs runtime blockchain lookups through public RPC providers, retrieves encoded configuration from smart-contract storage or transaction fields, decrypts or decodes the returned data, and then contacts the resolved infrastructure for further instructions or payload delivery. In observed campaigns, this has supported remote tasking, payload staging, credential and wallet theft, persistence, reconnaissance, and broader post-compromise activity. EtherHiding is best understood as a C2-hiding and staging mechanism rather than a standalone malware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The malware does not rely on a fixed traditional server for its instructions. Instead, it queries Ethereum smart contracts to retrieve live command-and-control, or C2, details. This approach is called EtherHiding.
The malware does not rely on a fixed traditional server for its instructions. Instead, it queries Ethereum smart contracts to retrieve live command-and-control, or C2, details. This approach is called EtherHiding.
The malware does not rely on a fixed traditional server for its instructions. Instead, it queries Ethereum smart contracts to retrieve live command-and-control, or C2, details. This approach is called EtherHiding.
The RAT issues an eth_call to read attacker data straight off a smart contract, which is an encrypted next-stage C2 address or config... This is EtherHiding.
The malware abuses Chromium browser trust mechanisms to install the extension without user approval and uses EtherHiding to retrieve its command-and-control infrastructure from the blockchain, making detection and takedown more difficult.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
EtherHiding is described as the mechanism used by ChainDrop to retrieve additional payload components via the Ethereum network, helping conceal attacker infrastructure and delivery.
EtherHiding is referenced as a malicious delivery/hosting technique used to conceal or retrieve payloads through blockchain/Ethereum-based infrastructure.
Referenced for comparison as a blockchain-based technique that stores command data in transaction calldata or smart contracts.
A blockchain-based malware infrastructure technique that stores command data in Ethereum transaction calldata or smart contracts to provide resilient command-and-control redirection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.