EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials
EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and (TL-2026-2600), also tracked as EtherHiding (Polygon Campaign), is a critical-severity malware campaign, first published 2026-09-21. It has no confirmed attribution, affects Multiple (WordPress/CMS site operators) 31 compromised legitimate, maps to 15 MITRE ATT&CK techniques (T1008, T1027, T1033), and is covered by 9 detection rules and 28 indicators of compromise.
Key facts for TL-2026-2600
- Threat ID
- TL-2026-2600
- Also known as
- EtherHiding (Polygon Campaign)
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-09-21
- Last reviewed
- 2026-09-21
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- financial services, banking, cryptocurrency, ecommerce, professional services, retail logistics
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 28
Malware and tooling in EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and
Malware and tooling: bpknfkhjjbjgagobdaekmnlgdhbbpcea
A campaign active since at least November 2025 has compromised 31 legitimate business websites and rotated 15 Polygon smart contracts across six operational waves to resolve command-and-control infrastructure, evolving from a PowerShell backdoor into a real-time banking trojan and malicious browser extension that intercepts credentials and 2FA codes across roughly 479 targeted financial and cryptocurrency domains.
How EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and works
EtherHiding is a technique first documented by Guardz in October 2023, in which adversaries host a pointer to their live command-and-control (C2) infrastructure inside a public blockchain smart contract rather than hardcoding it into malware, letting operators rotate C2 domains via a cheap on-chain transaction instead of re-deploying payloads. The technique was originally observed on Binance Smart Chain in the ClearFake fake-browser-update campaign. GuidePoint Security's DFIR team documented a distinct, Polygon-based evolution of the technique active since at least November 2025, in which victims of at least 31 compromised legitimate business websites (e-commerce, professional services, and retail-logistics operators) are shown a fake CAPTCHA / 'ClickFix' overlay instructing them to press Win+R and paste a PowerShell one-liner, which downloads a PowerShell backdoor from an attacker-controlled '.fun'/'.xyz'/'.online' delivery domain.
Once running, the backdoor performs a free, read-only `eth_call` against a hardcoded Polygon smart contract (observed contracts include 0xde2d34339c279a7a79bc4fc1c4f37d3c055211b7 and sibling 0xa982e044217b6bbaa7b3123b670c1c0ca1138a37, controlled by operator wallets 0xd802C9427ce416B9DAb2db5aDD76EfAA6d9d826a and 0x6a6e177dcf992ac16f7367c14b26a3cf4775dfde), using any of nine hardcoded public Polygon RPC endpoints for redundancy. The contract's return data is an obfuscated string that decodes, via a custom XOR cipher (key `!sdf$&G321`), to the current live C2 domain -- letting the operators rotate active C2 (observed: hivinest.online, insinght.site, 3262d48df5d75e34.shop, ddcd62e16a428c8e.shop, dsgnfwd.xyz, hubcreative.shop) at will while the malware binary and delivery chain stay unchanged. Across the campaign's seven-month lifespan the operators deployed 15 such contracts over six operational waves.
The implant establishes persistence via an HKCU\Software\Microsoft\Windows\CurrentVersion\Run registry value named 'PersonalizedUpdates' and a Scheduled Task named 'Enter' that re-executes the loader roughly every 60 seconds (the task is subsequently deleted by the malware to reduce forensic footprint). It fingerprints each victim by combining the Windows MachineGuid (HKLM\SOFTWARE\Microsoft\Cryptography), hostname, and username into a victim ID, and communicates with C2 over HTTP using the Authorization header as a covert data channel.
Over the campaign's lifetime the payload evolved from a general-purpose PowerShell remote-access backdoor into a real-time banking trojan, and operators added a fake malicious browser extension (extension ID bpknfkhjjbjgagobdaekmnlgdhbbpcea, communicating via native messaging host `com.top.index`) that intercepts banking and cryptocurrency-exchange login credentials and 2FA/OTP codes as victims type them, targeting an estimated 479 financial-services and cryptocurrency domains via web-inject-style interception panels (observed: purplepencel.online, detsigen.site). One piece of staging infrastructure identified in the investigation, onemm.net (origin IP 37.27.52.152), was itself found running seven CISA KEV-listed vulnerabilities, including CVE-2024-6387 (regreSSHion), indicating opportunistic infrastructure reuse rather than hardened operator tradecraft.
GuidePoint Security's public disclosure notes that the blockchain's immutability cuts both ways: while it lets operators cheaply rotate C2 without redeploying malware, every contract-update transaction is permanently and publicly recorded, letting defenders reconstruct the full operational timeline and pivot from one wallet or contract to related infrastructure. GuidePoint did not attribute the campaign to a named threat actor or group; the credential-theft focus and banking/crypto targeting indicate a financially motivated cybercriminal operation. Separately, GuidePoint and other researchers note the broader EtherHiding technique itself (independent of this specific Polygon campaign) has since been adopted by North Korea-linked state actors (from late 2025) and Iran-linked groups (from early 2026), reflecting wider tradecraft diffusion of blockchain-based C2 resolution across the threat landscape.
MITRE ATT&CK techniques used in TL-2026-2600
Command and Control
T1008 Fallback Channels; T1071.001 Web Protocols; T1102.001 Dead Drop Resolver
Defense Evasion
T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information
Discovery
T1033 System Owner/User Discovery; T1082 System Information Discovery
Persistence
T1053.005 Scheduled Task; T1176.001 Browser Extensions; T1547.001 Registry Run Keys / Startup Folder
Credential Access
T1056.004 Credential API Hooking
Execution
T1059.001 PowerShell; T1204.004 Malicious Copy and Paste
Resource Development
Affected products and versions in EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and
- Multiple (WordPress/CMS site operators) — 31 compromised legitimate business websites (e-commerce, professional services, retail logistics) used to host the ClickFix injection
Vulnerable versions: N/A -- content-injection compromise of legitimate sites, not a software version vulnerability - Financial services and cryptocurrency sector — End users of approximately 479 targeted banking and cryptocurrency-exchange domains
Vulnerable versions: N/A -- credential theft via malicious browser extension and web-inject panel, not a software vulnerability - Google / Chromium — Chromium-based browsers accepting the rogue extension (ID bpknfkhjjbjgagobdaekmnlgdhbbpcea)
Vulnerable versions: Any version permitting unmanaged/unapproved extension installation
Remediation for EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and
Immediate actions
- Block the identified C2 and delivery domains (hivinest.online, insinght.site, 3262d48df5d75e34.shop, ddcd62e16a428c8e.shop, dsgnfwd.xyz, hubcreative.shop, 45a3158594d6ba76.fun, 82d35f9b891c987a.fun, 9082b2a18f2e00fe.fun, veruisuealx.xyz, purplepencel.online, detsigen.site) at DNS/proxy layer
- Hunt for the 'Enter' scheduled task (including recently-deleted task remnants in Task Scheduler event logs) and the 'PersonalizedUpdates' HKCU Run key across Windows endpoints
- Identify and remove the malicious browser extension (ID bpknfkhjjbjgagobdaekmnlgdhbbpcea) and its native messaging host 'com.top.index' from affected browsers
- Force credential resets and 2FA/OTP re-enrollment for any user who interacted with a ClickFix prompt on a compromised site or had the rogue extension installed
- Audit any public-facing site for injected fake-CAPTCHA/ClickFix overlays, since GuidePoint observed re-compromise of previously cleaned sites weeks later
Workarounds
- Restrict outbound access from standard end-user endpoints to public Polygon RPC endpoints (polygon-bor-rpc.publicnode.com, polygon.publicnode.com, polygon.gateway.tenderly.co, gateway.tenderly.co, 1rpc.io, polygon.api.onfinality.io, polygon.rpc.subquery.network, polygon.drpc.org, polygon.lava.build) where no legitimate Web3 business need exists
- Apply Windows AppLocker/WDAC or PowerShell Constrained Language Mode to reduce the impact of ClickFix-style Win+R-and-paste PowerShell execution
Longer-term hardening
- Enforce browser-extension allow-listing via organization-level policy rather than relying on marketplace review alone
- Continuously re-audit and integrity-monitor public-facing WordPress/CMS sites for injected content -- one-time cleanup is insufficient
- Deploy behavioral/DGA-pattern and ASN/hosting-reputation detection for C2 identification rather than relying on static domain or IP blocklists, since blockchain-resolved C2 domains rotate cheaply
- Add ClickFix-style paste-and-run social engineering to security-awareness training as a distinct scenario from generic phishing
- Monitor outbound HTTP traffic for anomalous use of the Authorization header as a data channel to non-corporate domains
Timeline of EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and
- Guardz first documents the 'EtherHiding' technique: threat actors behind the ClearFake campaign host obfuscated next-stage payload pointers inside a Binance Smart Chain contract, retrieved via a standard eth_call, establishing the blockchain-dead-drop-resolver approach later reused on Polygon.
- First of six identified operational waves begins; the operators start deploying and rotating Polygon smart contracts as C2 address resolvers, eventually totaling 15 contracts across the campaign's seven-month lifespan.
- GuidePoint Security's DFIR team observes the earliest activity for this campaign: a general-purpose PowerShell backdoor delivered via ClickFix fake-CAPTCHA overlays injected into compromised legitimate business websites, resolving C2 via a hardcoded Polygon smart contract.
- Approximate mid-campaign point at which the payload evolves from a general-purpose remote-access PowerShell backdoor into a real-time banking trojan capable of intercepting login credentials and 2FA/OTP codes as victims type them.
- Operators add a fake malicious browser extension (ID bpknfkhjjbjgagobdaekmnlgdhbbpcea, native messaging host com.top.index) to intercept banking and cryptocurrency-exchange credentials in real time, expanding targeting to an estimated 479 financial and crypto domains.
- Sixth and final identified operational wave concludes, completing roughly seven months of C2 infrastructure rotation across 15 Polygon smart contracts and at least 31 compromised legitimate websites.
- GuidePoint Security publishes 'EtherHiding Exposed,' its deep-dive technical analysis of the Polygon-based campaign, including persistence and C2 mechanics, IOCs, and defensive guidance.
- GBHackers republishes coverage of GuidePoint's findings, broadening industry awareness and tracking of the campaign.
Sources cited for EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and
- EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials
- EtherHiding Exposed: Inside a Blockchain-powered Malware Campaign Hiding in Plain Sight
- EtherHiding Exposed: What Security Leaders Need to Know
- EtherHiding Exposed: Inside a Blockchain-powered Malware Campaign Hiding in Plain Sight (reprint)
- EtherHiding Exposed: What Security Leaders Need to Know (reprint)
- Binance's Smart Chain Exploited in New 'EtherHiding' Malware Campaign
- EtherHiding: A Novel Technique to Hide Malicious Code Using Binance's Smart Chain
- Cribl SecOps uncovers EtherHiding malware campaign on the blockchain
More in malware
- Trusted AI Platforms Weaponized as Malware Distribution Channels: Claude Artifacts, ChatGPT, and Grok Abused Across SectopRAT, MacSync, and AMOS Campaigns
- Rapuncel Infostealer Uses Microsoft-Signed Driver to Kill 145 Security Tools via Fake LastPass Authenticator GitHub Repos
- Jade Sleet (North Korea) Compromises Indian IT Provider via FLATROOF and ROOFDECK macOS Backdoors
- PowerShell Cryptomining Loader Abuses Registry-Resident Scripts, DNS TXT Records, and PNG/WAV Steganography for Stealth C2
- RatHat: AI-Powered Android Banking Trojan Abuses Accessibility Service and ADB to Steal Credentials, PINs, and MFA Codes
Detection coverage for TL-2026-2600
As of 2026-09-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2600 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.