Hackers Hide Malware Servers on Blockchain to Steal Bank Logins and 2FA Codes
Malware operators hide C2 in Polygon blockchain contracts via EtherHiding, delivering a browser-based banking trojan that steals bank logins and 2FA codes from 479 sites.
GuidePoint Security uncovered a campaign active since at least November 2025 that injected JavaScript into at least 31 legitimate websites to show fake CAPTCHA prompts. Victims who paste the PowerShell command into Windows Run get a scheduled task named Enter and a backdoor that queries 15 observed Polygon smart contracts for its current C2 address, a technique known as EtherHiding. The backdoor installed a browser-extension banking trojan targeting roughly 479 financial and cryptocurrency sites, intercepting credentials and 2FA codes with web-injects, keylogging, screen capture, and wallet theft. Some infrastructure, including active C2 domains and an exposed build server with seven actively exploited vulnerabilities, remains live.