EtherHiding Campaign Uses WebRTC Data Channels for Covert Command and Control

· Original article ↗

Summary

Netskope found EtherHiding malware on more than 5,400 compromised websites. The campaign retrieves scripts from BNB Smart Chain testnet contracts and includes a WebRTC variant that opens a covert command channel without normal signaling.

Key points

  • Netskope observed more than 5,400 compromised sites across 2,200-plus organizations, with hundreds active on a typical day. The sites were mostly small businesses; many examined sites used WordPress or PrestaShop.
  • How the sites were initially compromised is unknown. Injected inline scripts or spoofed packages retrieve and execute payloads stored in BNB Smart Chain testnet smart contracts.
  • The usual delivery chain presents a ClickFix fake CAPTCHA that instructs visitors to run a command, which downloads and launches the final payload.
  • A newer variant uses a WebRTC data-channel stager. It forges the session-description answer locally, avoiding signaling traffic while opening an encrypted channel to the attacker.
  • The stager executes code received over the channel in the browser and reuses a legitimate script’s Content Security Policy nonce when available.
  • Netskope recommends blocking the full BSC-testnet RPC endpoint pool and monitoring non-web traffic for the WebRTC channel. Site owners should integrity-check CMS assets and plugin directories.

Article Details

Attack Vectors
  • Compromised websites deliver an injected inline script or spoofed package to visitors. The initial method of site compromise is unknown.
  • The loader retrieves and runs a second-stage script from a BSC testnet smart contract using a JSON-RPC eth_call.
  • One second stage displays a fake CAPTCHA overlay that instructs visitors to run a pasted downloader command.
  • A newer variant opens a WebRTC data channel to a cyberattacker-controlled C2, receives code through the channel, and executes it in the browser.
Defensive Notes
  • Block the full BSC-testnet RPC endpoint pool rather than only the primary endpoint.
  • Monitor non-web traffic for the WebRTC channel, which HTTP inspection does not see.
  • Site owners should integrity-check CMS assets for loaders appended to legitimate JavaScript files or placed in fake plugin directories.

MITRE ATT&CK

Vendors

Products

Industries

Related Articles