Skip to main content
Packetlabs Company Logo
Blog

EtherHiding: Hiding Malware On the Blockchain

Authored By Packetlabs

|
EtherHiding: Hiding Malware On the Blockchain

Would you like to learn more?

Download our Pentest Sourcing Guide to learn everything you need to know to successfully plan, scope, and execute your penetration testing projects.

So far, Bitcoin has stood the test of time. Although the cryptocurrency is a vector for scams, criminal activity, and its users the target of cyber attacks such as spam and phishing, account compromise, InfoStealer malware, Bitcoin's underlying blockchain technology has remained largely technically resilient to cryptographic attacks. However, blockchain technology, so often lauded for its security, can also be leveraged by threat actors, creating a new dimension in cybersecurity challenges across the broader cryptocurrency ecosystem.

Since blockchain emerged, thousands of cryptocurrencies have spawned, most of them leveraging a ++decentralized finance model++. And other uses for blockchain have emerged such as smart contracts and their flagship crypto product Ethereum. Ethereum has been on the radar for cyber crime already. Hackers actively seek out and ++compromise smart contracts++ to steal the cryptocurrency funds they hold.

In late 2023, a new use case for Ethereum emerged known as EtherHiding. This time instead of hacking into smart contracts to rob them, attackers are leveraging them to ++host malware++ that the attackers can later access and download onto compromised systems. In this article we will learn about EtherHiding, how it helps solve a problem of detection for hackers, and review some recent attack campaigns that have used EtherHiding.

What is EtherHiding?

EtherHiding is a new cyber attack technique discovered in October 2023, a sophisticated form of cyberattack that leverages blockchain technology to covertly host malware within the cryptocurrency landscape. The term "EtherHiding" can be misleading, because the technique can use a number of smart contract platforms, not only Ethereum.

Cyberattacks that involve malware infection typically happen in two distinct phases.

  • The first phase is to gain unauthorized access to a victim's system.

  • The second phase is to import malware to the system and execute it.

During the second stage, cyber criminals face the challenge of covertly importing their malware to the victim's system, while protecting their identity by removing any traces of their connection to the malware code. One technique used by attackers to keep their malware accessible and protect their identity is known as BulletProof hosting. However, even using rogue hosting services, defenders can block the source IP address or domain where the malware is stored once they discover it.

The new EtherHiding tactic is especially effective at preventing defenders from easily blocking the malware's location by leveraging blockchain's properties.

  • Blockchain transaction anonymity makes it difficult to trace the identity of attackers, while the irreversibility of blockchain means the malware will forever be embedded in the blockchain and cannot be deleted.

  • Finally, since most blockchains are decentralized, it is virtually impossible for authorities to issue takedown notices that can effectively remove the malicious code from the Internet or to block the malware's source IP via firewall rules. This is because decentralized blockchain technology is hosted across many IP addresses, which are difficult or even impossible to completely track.

How Does EtherHiding Work?

EtherHiding works by exploiting the decentralized nature of blockchain platforms, with a particular focus on the Binance Smart Chain (BSC). Cybercriminals use BSC's smart contracts to host malicious code. Smart contracts, once deployed, because they are hosted on the blockchain, are resistant to takedowns. Also, by embedding the malicious code in the blockchain, attackers don't need to have extensive malware files on their victim's system, thwarting detection efforts across the Binance ecosystem.

Here is how EtherHiding works:

  • The attacker embeds malicious JavaScript within web pages of compromised websites such as

    hacked WordPress sites, which reaches out and interacts with the smart contract to retrieve malware payloads via Binance's Software Development Kit (SDK).

  • The eth_call method on the BSC is commonly used to fetch the malicious code without leaving a trace in the blockchain's transaction logs.

  • This makes EtherHiding an incredibly resilient method of attack, with little recourse for takedowns even after detection.

  • Because BSC is decentralized, it can be hosted on a wide number of IP addresses making rule-based detection impossible.

  • Consequently, websites running on outdated software or weak security configurations are particularly vulnerable to such attacks.

Known Attacks That Used EtherHiding

  • One notable cyber attack campaign that used EtherHiding is the "ClearFake" campaign, where cybercriminals compromised WordPress-based websites by injecting hidden JavaScript code into article pages.

  • In another case, EtherHiding was used with Fake-Updates, a tactic where users were tricked into downloading malware disguised as software updates. Victims were presented with pop-ups prompting them to download what appeared to be legitimate updates, but these actually delivered malicious code via the blockchain, leading to site defacement and malware infections.

Conclusion

EtherHiding leverages the decentralized nature of blockchain, particularly the Binance Smart Chain, to conceal and distribute malicious code via smart contracts.

This tactic exploits blockchain's anonymity and resistance to takedowns, making it highly effective and difficult to trace.

Recent cases, like the ClearFake campaign, demonstrate how EtherHiding facilitates sophisticated cyberattacks, creating new challenges for defenders in detecting and mitigating these threats.

Join our newsletter

Uncover exploitable weaknesses before attackers do.

Book your discovery call with our team of Offensive Security experts.

Packetlabs Company Logo
  • Toronto | HQ401 Bay Street, Suite 1600
    Toronto, Ontario, Canada
    M5H 2Y4
  • San Francisco | Outpost580 California Street, 12th floor
    San Francisco, CA, USA
    94104
  • Calgary | Outpost421 - 7th Ave SW, Suite 3000
    Calgary AB, Canada
    T2P 4K9
  • Australia | OutpostPacketlabs Pty Ltd.
    ABN 14 691 178 542
    Level 24, 1 O'Connell St
    Sydney NSW 2000
Cyber Right NowCREST LogoCREST AI Signatory AICPA SOC 2 LogoG2Clutch 2023 Certification Logo