EtherHiding Malware Uncovered: Sophisticated Threat Targets Polygon Users
Security researchers have uncovered a sophisticated cyber threat known as EtherHiding that targets cryptocurrency users. The malware, which has been linked to several domains and infrastructure, is designed to evade detection by using complex techniques.
The attackers have set up multiple domains, including shopddcd62e16a428c8e[.]shop, deliverdomains like 45a3158594d6ba76[.]fun, and support infrastructure onemm[.]net. The latter is running several critical vulnerabilities listed by CISA KEV.
The malware also uses a combination of browser extension web-inject panels, including Purplepencel[.]online and Detsigen[.]site, to inject malicious code into cryptocurrency websites. It targets Polygon (MATIC) users, with the primary smart contract being 0xde2d34339c279a7a79bc4fc1c4f37d3c055211b7.
Researchers have also identified multiple RPC endpoints used by the attackers to interact with the Polygon network. Additionally, the malware sets up a scheduled task called 'Enter' that runs at one-minute intervals and uses an XOR key of !sdf$&G321.