logo

Hiding in the Chain: Multi-Stage LNK Attack Leveraging TON Blockchain to Deliver Node.JS Backdoor

ID: ef417cb0-f7a2-5491-b940-57b4bf879417

STIX ID: report--ef417cb0-f7a2-5491-b940-57b4bf879417

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
75/100

Date Published: 2026-07-09

Date Updated: 2026-07-19

Author: Nathaniel Morales

...
...

This report analyzes an active multi-stage malware campaign that uses malicious ZIP/LNK dropper files to execute obfuscated PowerShell which installs a legitimate Node.js runtime and launches a heavily obfuscated Node.js backdoor. The backdoor retrieves C2 by querying a TON blockchain smart contract (EtherHiding), establishes an encrypted WebSocket channel with ECDH/HKDF/AES-256-CBC, supports remote payload execution, achieves persistence via HKCU Run registry entries, and is distributed via spam and public forums with numerous observed samples and domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.