Remus Malware Leverages Ethereum Smart Contracts for Dynamic Command-and-Control
Hackers have discovered a new way to use Ethereum smart contracts as a dead-drop resolver for the Remus malware. This campaign uses fake cracked software lures and Turkish-language SEO poisoning to trick victims into downloading malicious software.
The Remus malware issues a JSON-RPC eth_call request to a hardcoded Ethereum smart contract via a public RPC endpoint, which returns an encoded C2 URL that the malware decodes at runtime.
The malware then uses this URL for HTTP-based exfiltration, sending stolen data to domains such as fimmora.surf and zelpx.garden. The infrastructure behind this campaign is not exclusive to a single family, with multiple sibling domains hosted on shared cloud infrastructure nodes.