EtherHiding Malware Hides C2 in Polygon Blockchain Smart Contracts to Deliver Banking Trojan Targeting ~479 Finance and Crypto Sites
Attackers inject fake CAPTCHA overlays into at least 31 legitimate websites, tricking users into running a PowerShell command that installs a backdoor which resolves its live C2 address from 15 Polygon smart contracts (EtherHiding) and drops a…
GuidePoint Security researchers uncovered an EtherHiding campaign, active since at least November 2025 (GBHackers describes the start as 'late 2025'), that injects JavaScript into at least 31 legitimate websites to display fake CAPTCHA prompts. Victims who paste a PowerShell command into Windows Run get a scheduled task named 'Enter' and a backdoor with persistence (registry keys per GBHackers) that queries 15 observed Polygon smart contracts for its current C2 address, allowing operators to rotate C2 domains via cheap blockchain transactions and evade takedowns. The backdoor installs a browser-extension banking trojan targeting approximately 479 financial and cryptocurrency domains, intercepting credentials and 2FA codes through web-injects, keylogging, screen capture, and crypto wallet theft. The campaign remains active, with live C2 domains and an exposed build/staging server running seven actively exploited vulnerabilities.
- Technique: EtherHiding — C2 configuration stored in 15 observed Polygon blockchain smart contracts, letting operators swap C2 addresses without modifying the deployed payload
- Initial access: JavaScript injected into at least 31 legitimate websites shows fake CAPTCHA overlays prompting victims to paste a PowerShell command into Windows Run
- Persistence: a scheduled task named 'Enter' (Cyber Security News); GBHackers also reports persistence via registry keys
- Payload: browser-extension backdoor/banking trojan targeting approximately 479 financial and cryptocurrency domains
- Capabilities: web-injects to intercept credentials and 2FA codes, keylogging, screen capture, and crypto wallet theft
- Timeline: active since at least November 2025 per GuidePoint Security (GBHackers: 'late 2025'); still active as of the September 21, 2026 reports
- Live infrastructure: active C2 domains remain up, and researchers found an exposed build/staging server running seven actively exploited vulnerabilities
- Attribution/discovery: uncovered by GuidePoint Security (reported by Cyber Security News); GBHackers separately reported the Polygon-based C2 and the ~479-domain target list
Coverage timelineoldest first · each row is one article
- · 6d agoEtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials
GBHackers· 85
EtherHiding malware uses Polygon blockchain smart contracts for resilient C2 and steals banking credentials from nearly 500 targeted domains.
- · 5d agoHackers Hide Malware Servers on Blockchain to Steal Bank Logins and 2FA Codes
Cyber Security News· 72
Malware operators hide C2 in Polygon blockchain contracts via EtherHiding, delivering a browser-based banking trojan that steals bank logins and 2FA codes from 479 sites.