EtherHiding Campaign Uses WebRTC Data Channels for Covert Command and Control

Summary
Netskope found EtherHiding malware on more than 5,400 compromised websites. The campaign retrieves scripts from BNB Smart Chain testnet contracts and includes a WebRTC variant that opens a covert command channel without normal signaling.
Key points
- Netskope observed more than 5,400 compromised sites across 2,200-plus organizations, with hundreds active on a typical day. The sites were mostly small businesses; many examined sites used WordPress or PrestaShop.
- How the sites were initially compromised is unknown. Injected inline scripts or spoofed packages retrieve and execute payloads stored in BNB Smart Chain testnet smart contracts.
- The usual delivery chain presents a ClickFix fake CAPTCHA that instructs visitors to run a command, which downloads and launches the final payload.
- A newer variant uses a WebRTC data-channel stager. It forges the session-description answer locally, avoiding signaling traffic while opening an encrypted channel to the attacker.
- The stager executes code received over the channel in the browser and reuses a legitimate script’s Content Security Policy nonce when available.
- Netskope recommends blocking the full BSC-testnet RPC endpoint pool and monitoring non-web traffic for the WebRTC channel. Site owners should integrity-check CMS assets and plugin directories.
Article Details
- Attack Vectors
- Compromised websites deliver an injected inline script or spoofed package to visitors. The initial method of site compromise is unknown.
- The loader retrieves and runs a second-stage script from a BSC testnet smart contract using a JSON-RPC eth_call.
- One second stage displays a fake CAPTCHA overlay that instructs visitors to run a pasted downloader command.
- A newer variant opens a WebRTC data channel to a cyberattacker-controlled C2, receives code through the channel, and executes it in the browser.
- Defensive Notes
- Block the full BSC-testnet RPC endpoint pool rather than only the primary endpoint.
- Monitor non-web traffic for the WebRTC channel, which HTTP inspection does not see.
- Site owners should integrity-check CMS assets for loaders appended to legitimate JavaScript files or placed in fake plugin directories.
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe article describes an obfuscated inline loader and a WebRTC stager that constructs its C2 IP address from separate numbers rather than storing it as a string.T1059.001 · PowerShellThe ClickFix lure places a PowerShell downloader command on the visitor's clipboard for them to run.T1059.007 · JavaScriptThe loader executes JavaScript retrieved from a smart contract; the WebRTC variant also executes JavaScript received through its data channel.T1071 · Application Layer ProtocolThe newer stager uses a WebRTC data channel over UDP to receive code from the cyberattacker's C2.T1105 · Ingress Tool TransferThe command presented by the ClickFix lure downloads and runs a final payload.T1189 · Drive-by CompromiseInjected scripts on compromised websites run in visitors' browsers when the pages load.T1204 · User ExecutionA fake CAPTCHA overlay instructs visitors to open a Run dialog and execute a pasted command.
Vendors
Products
BNB Smart ChainNetskope telemetry flagged thousands of small-business websites making the same unusual request, a JSON-RPC call to a BNB Smart Chain (BSC) testnet endpoint.PrestaShopWhere we examined individual sites, they were most often WordPress, and sometimes PrestaShop.WordPressWhere we examined individual sites, they were most often WordPress, and sometimes PrestaShop.