<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>EtherHiding on</title><link>/tags/etherhiding/</link><description>Recent content in EtherHiding on</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 17 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="/tags/etherhiding/index.xml" rel="self" type="application/rss+xml"/><item><title>EtherHiding Attack Chain</title><link>/posts/etherhidingattackchain/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>/posts/etherhidingattackchain/</guid><description>&lt;ul>
&lt;li>Reading time : &amp;ldquo;13 min&amp;rdquo;&lt;/li>
&lt;/ul>
&lt;h1 id="clickfix-phishing-campaign-with-etherhiding">ClickFix Phishing Campaign with EtherHiding&lt;/h1>
&lt;h2 id="executive-summary">Executive Summary&lt;/h2>
&lt;p>This report documents an active, sophisticated multi-stage attack campaign observed across hundreds of compromised WordPress websites. The campaign fuses two advanced techniques: &lt;strong>ClickFix&lt;/strong> social engineering — which tricks users into manually executing malicious commands — and &lt;strong>EtherHiding&lt;/strong>, a persistence mechanism that stores malware payloads directly on the Binance Smart Chain (BSC), making takedown nearly impossible.&lt;/p>
&lt;p>Researchers identified over &lt;strong>400 sandbox analyses on ANY.RUN&lt;/strong> linked to this campaign&amp;rsquo;s infrastructure, with C2 domains &lt;code>dntds.shop&lt;/code> and &lt;code>sdntds.shop&lt;/code> observed in active use as recently as &lt;strong>June 13, 2026&lt;/strong>. The final payload is a PowerShell-based shellcode loader that downloads and executes a binary from a bulletproof-hosted IP (&lt;code>158[.]94[.]208[.]92&lt;/code> / &lt;code>158[.]94[.]208[.]104&lt;/code>), consistent with infostealer or RAT deployment.&lt;/p></description></item></channel></rss>