Product
Ethereum
- First Reported
- Aug 4, 2026
- Latest Reported
- Oct 1, 2026
Reported Context (3)
- Rather than a single hardcoded server, the payload carries a list of roughly twenty public Ethereum RPC gateways and a set of smart-contract method selectors. It sends requests to those gateways to read SC WordPress Malware Uses Self-Rebuilding Loaders and Blockchain-Controlled Backdoor
- In one case, attackers installed it from its official site to run an implant commanded via the Ethereum blockchain. Attackers Revive Node.js Abuse to Run Malware and Maintain Persistence
- executed MSI payloads. Those installed EtherRAT, a persistent implant that pulls its C2 domains from an Ethereum smart contract instead of hardcoding them, while Sliver and Go reverse-shell binaries gave the operator The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum-Based C2
CVE (1)
Malware (15)
Threat Actors (2)
MITRE ATT&CK (27)
Vendors (3)
Products (5)
Tools (12)
Industries (8)
Countries (5)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.