logo

Hackers Abuse Ethereum Smart Contracts to Hide Amatera Stealer C2 Servers

ID: 04f8c179-c142-5755-b0e4-95b6be0b14bc

STIX ID: report--04f8c179-c142-5755-b0e4-95b6be0b14bc

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

This report details an active campaign using trojanized archives and a Ren'Py-based loader (RenPy/RenEngine Loader) to deliver Amatera Stealer and other payloads; the loader performs sandbox checks, uses LOLBIN techniques (forfiles.exe, MSBuild.exe), reconstructs a trojanized Nancy.NET in memory, and employs heavy obfuscation. Notably, the campaign uses an EtherHiding technique—querying an Ethereum JSON-RPC endpoint to retrieve encrypted C2 information—making takedown and detection more difficult. Distribution occurs via malicious and spoofed download sites and popular file-sharing platforms, and the report includes multiple domains and IPs as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.