Hiding in the Chain: Multi-Stage LNK Attack Leveraging TON Blockchain to Deliver Node.JS Backdoor
ID: ef417cb0-f7a2-5491-b940-57b4bf879417
STIX ID: report--ef417cb0-f7a2-5491-b940-57b4bf879417
Feed Name: LevelBlue SpiderLabs Blog
This report analyzes an active multi-stage malware campaign that uses malicious ZIP/LNK dropper files to execute obfuscated PowerShell which installs a legitimate Node.js runtime and launches a heavily obfuscated Node.js backdoor. The backdoor retrieves C2 by querying a TON blockchain smart contract (EtherHiding), establishes an encrypted WebSocket channel with ECDH/HKDF/AES-256-CBC, supports remote payload execution, achieves persistence via HKCU Run registry entries, and is distributed via spam and public forums with numerous observed samples and domains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
