Tag: blockchain
-
North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign
The FBI and Defense Department partnered with Japan’s National Police Agency and law enforcement agencies in Australia and Germany on a new advisory about “WaterPlum”, a group of cyber actors allegedly stealing cryptocurrency from job applicants by posing as AI or blockchain companies. First seen on therecord.media Jump to article: therecord.media/north-korean-hackers-infect-thousands-of-devices-waterplum-scheme
-
MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana for C2
A newly identified Windows malware framework dubbed MovieReaper is being distributed through pirated movie torrents after threat actors compromised a public torrent-file repository used by multiple tracker sites. The campaign combines a multi-stage infection chain, anti-analysis techniques, UAC bypass, file-management capabilities, and Solana blockchain-based command-and-control (C2) discovery to make disruption more difficult. Kaspersky researchers identified…
-
TRM Labs Lands $2B Valuation as AI Expands Investigations
TRM Platform Uses AI to Marry Blockchain Data With Registries, Threat Intelligence. TRM Labs reached a $2 billion valuation as it uses AI to combine blockchain transactions with ownership, corporate and threat intelligence data, giving investigators a broader view of criminal and nation-state networks and potential points for disruption. First seen on govinfosecurity.com Jump to…
-
Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/over-5-400-hacked-sites-serve-clickfix-payloads-stored-on-the-blockchain/
-
Cryptohack Roundup: US Seizes Hamas-Linked Crypto
Also: ClickFix Attack Abuses Polygon Blockchain. This week, U.S. seizes Hamas-linked funds, ClickFix attack abuses Polygon blockchain, Bithumb wins lawsuit over bitcoin credit error, software flaw exposes six Cosmos networks, Cronos restarts after Tectonic attack and Moonwell investigates $8.7 million exploit. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/cryptohack-roundup-us-seizes-hamas-linked-crypto-a-32734
-
ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain
The campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/clickfix-campaign-comprises-31-orgs-abuses-polygon-blockchain
-
Cronos blockchain restarts after $74 million Tectonic exploit
The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cronos-blockchain-restarts-after-74-million-tectonic-exploit/
-
Hundreds of WordPress Sites Hijacked to Show Fake reCAPTCHA and Steal Windows Passwords.
Hundreds of compromised WordPress websites are being used in a sophisticated malware-delivery campaign that combines browser persistence, blockchain-hosted payloads, fake reCAPTCHA prompts and fileless execution to deploy the Amatera information stealer on Windows systems. The campaign stands out for placing its malicious logic across nine layers designed to minimize durable evidence: no conventional payload server,…
-
Cryptohack Roundup: Term Finance Hack
Also: Fraud Convictions for Profit Connect and Block Bits Capital. This week, hackers stole $8.5M from Term Finance, BounceBit to shutter blockchain after hack, Profit Connect and Block Bits Capital founders convicted in fraud cases, Roman Storm’s retrial delayed and AI use in crypto-linked crime jumped 40%. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/cryptohack-roundup-term-finance-hack-a-32668
-
Arctic Wolf Labs entdeckt neues Malware-Framework <>
Ein neues Malware-Framework in zwei unterschiedlich umfangreichen Ausführungen und ein Ausweichmechanismus über die Ethereum-Blockchain: Arctic Wolf Labs hat bei der Untersuchung eines gezielten Angriffs auf eine Organisation aus dem Kommunikationssektor in Venezuela die bislang nicht dokumentierte Malware <> entdeckt. Arctic Wolf ordnet den Angriff mit mittlerer Sicherheit der Cyberspionage-Gruppe Dark Caracal zu. Die wichtigsten Erkenntnisse…
-
Fake Claude Desktop Installer Deploys SectopRAT Using DLL Sideloading and Blockchain C2
A fake Claude Desktop installer campaign is using Bing malvertising to impersonate trusted Claude. ai-hosted content, DLL sideloading, and blockchain-based command-and-control to deploy the SectopRAT remote-access trojan. CyberProof researchers said an agent-led hunt scoped the full intrusion chain across endpoint telemetry in about ten minutes, turning a single suspicious scheduled task into a confirmed multi-stage…
-
PavinLoader Uses ClickFix and Fake Downloads to Deploy Amatera Stealer via Blockchain C2
PavinLoader, a multi-stage .NET malware loader, operating across ClickFix, fake software-download, and malicious game campaigns. The activity shows how attackers are moving beyond a single delivery vector. A victim may be lured to a fake Cloudflare or Google verification page and instructed to paste a command, persuaded to install apparently legitimate software, or tricked into…
-
Cryptohack Roundup: Harmony’s Post-Exploit Blockchain Rollback
Also: Fake Web3 Interview Led to Wallet Theft, Delio CEO’s 15-Yr Sentence. This week, Harmony to roll back blockchain after exploit, Delio CEO sentenced to 15 years in South Korea, an alleged Ponzi promoter deported to the United States, SafePal and Trezor customers’ data exposed, and attackers exploited a Mac flaw to mine Monero. First…
-
Aeternum Operators Use Polygon Smart Contracts to Rotate Malware C2 Domains Dynamically
Aeternum operators are abusing Polygon smart contracts as a decentralized dead-drop resolver, allowing malware to retrieve and rotate command-and-control (C2) domains without depending on conventional attacker-owned servers. The approach turns a public blockchain into resilient C2 infrastructure that is substantially harder to disrupt through domain seizures, hosting takedowns, or sinkholing. Rather than contacting a fixed…
-
News alert: OpenMatter Network spotlights AI verification at Belgrade Blockchain Week
Melbourne, Fla., August 17, 2026, CyberNewswire, Continuing its effort to build global awareness of the need to move computing from assumption-based trust to cryptographic proof, OpenMatter Network today announced that Head of Operations and Partnerships Chris Biele will play… (more”¦) First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/news-alert-openmatter-network-spotlights-ai-verification-at-belgrade-blockchain-week/
-
OpenMatter Network to Take Verification Message to Belgrade Blockchain Week 2026
Melbourne, Florida, August 17th, 2026, CyberNewswire Head of Operations and Partnerships Chris Biele to lead sessions on secure scientific collaboration, agentic AI and the need to move from trust to cryptographic proof Continuing its effort to build global awareness of the need to move computing from assumption-based trust to cryptographic proof, OpenMatter Network today announced…
-
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
Tags: blockchain, communications, data, extortion, group, infrastructure, leak, microsoft, network, ransomware, service, threatThe ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience.”Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process,” the Microsoft Threat First seen on thehackernews.com Jump…
-
ErrTraffic Combines WordPress Hacks, Blockchain C2 and Rotating Malware Domains in One Delivery Network
An active ErrTraffic malware-as-a-service campaign that combines compromised WordPress sites, ClickFix lures, Polygon blockchain smart contracts and rapidly rotating payload domains to distribute a broad set of Windows malware. ErrTraffic is marketed as a MaaS framework by a forum user known as “LenAI.” Its core feature is a traffic distribution system that routes victims to…
-
Blockchain and AI: Why Trusted Data Matters
The internet has crossed a threshold that content teams can no longer ignore. Independent analysis of tens of thousands of web pages found that mostly AI-generated articles accounted for an estimated 49.9% of sampled content published in the first quarter of 2026, a level that has held roughly steady since AI-written material briefly overtook human-written…
-
Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer.The new dead drop resolver approach, observed in two trojanized npm packages “bianira-ui” and “fluid-type-ui,” has been codenamed NullReceiver by First seen on thehackernews.com Jump…
-
Uppsala Security Becomes First Blockchain Intelligence Company to Join Cyber Threat Alliance
SIngapore, Singapore, August 5th, 2026, CyberNewswire Uppsala Security, a Singapore-based blockchain intelligence and crypto forensics company, announced today that it has joined the Cyber Threat Alliance (CTA) as an Affiliate Member, becoming the first blockchain intelligence company to join the alliance. CTA is a nonprofit organization that brings cybersecurity organizations together to share actionable threat…
-
Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer.The new dead drop resolver approach, observed in two trojanized npm package “bianira-ui” and “fluid-type-ui,” has been codenamed NullReceiver by First seen on thehackernews.com Jump…
-
Uppsala Security Becomes First Blockchain Intelligence Company to Join Cyber Threat Alliance
SIngapore, Singapore, 5th August 2026, CyberNewswire First seen on hackread.com Jump to article: hackread.com/uppsala-security-becomes-first-blockchain-intelligence-company-to-join-cyber-threat-alliance/
-
Ransomware Hackers Are Hiding Malware Command Servers Inside Ethereum Smart Contracts
Ransomware operators are now abusing Ethereum smart contracts as stealthy command”‘and”‘control resolvers, with a Gentlemen ransomware affiliate using the EtherRAT backdoor to pull rotating C2 domains directly from the blockchain instead of hardcoding them in the malware. The toolkit shows a clear progression: scheduled tasks that bootstrap PowerShell, privileged account creation (“support2” with Supp0rt2@2026!). LSASS…
-
Hackers steal over $130M by exploiting bug in offline hardware wallets
A security vulnerability in the cryptocurrency hardware wallet Coldcard is allowing hackers to drain the crypto from victims’ wallets. The total losses amount to more than $130 million, according to blockchain-monitoring firms. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/
-
Hackers steal over $130 million by exploiting bug in offline hardware wallets
A security vulnerability in the cryptocurrency hardware wallet Coldcard is allowing hackers to drain the crypto from victims’ wallets. The total losses amount to more than $130 million, according to blockchain monitoring firms. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/
-
NullReceiver Is Harder to Discover but Still Exposes a Reusable Attacker Wallet
NullReceiver is a lean, stealth-focused evolution of DPRK’s blockchain C2 tradecraft that hides a reusable attacker wallet behind ordinary-looking Ethereum transfers, while still exposing just enough bytes to resolve a live command server. Two trojanized npm packages, bianira-ui@1.27.0 and fluid-type-ui@2.0.8, both Tailwind CSS plugin lookalikes, implement a new blockchain-based C2 resolution technique we’re calling NullReceiver.…
-
Why Bitcoin Businesses Are Moving to Dedicated VPS Infrastructure
A Bitcoin business rarely runs a simple website. Payment processors, exchanges, wallet services, blockchain analytics products and Lightning… First seen on hackread.com Jump to article: hackread.com/bitcoin-businesses-dedicated-vps-infrastructure/
-
Coldcard Firmware Flaw Lets Hackers Steal $70 Million in Bitcoin From 1,196 Addresses
Blockchain analysts have linked a rapid series of Bitcoin wallet drains to a reported vulnerability in Coldcard firmware. A total of 1,196 addresses lost a combined 1,082.65 BTC, valued at approximately $70.2 million, in just 41 minutes on July 30, 2026. Galaxy Research stated that its transaction-flow analysis was based on a pattern initially identified…

