Minecraft Malware Loader Uses RSA-Signed Smart Contract Updates for Persistent C2
ID: 81563869-7093-54d1-9bd6-1dbe8c003fec
STIX ID: report--81563869-7093-54d1-9bd6-1dbe8c003fec
Feed Name: cybersecurityNews.com
A sophisticated malware campaign (LoaderClient/WeedHack) distributes a malicious Minecraft Fabric mod that harvests player session data—including live Microsoft OAuth access tokens—to enable account takeover and deliver an in-memory stage-two native payload. The loader resolves and verifies its C2 via an Ethereum smart contract (EtherHiding) with RSA-signed updates, uses DNS-over-HTTPS, encrypted strings, zip-bomb resources, and UAC bypass techniques to evade detection, and operates as a low-cost Malware-as-a-Service with extensive IoCs and persistent infrastructure; the report lists hashes, contract address, domains, endpoints, file paths, scheduled tasks, and recommended defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
