tag: Blockchain · 6 items
- Engineer — Plan: If your organization runs any Cosmos EVM-based chain, treat this as Act: the shared module (GHSA-7g4w-cg88-2cq2) was actively exploited Aug 20–25 and must be patched to ≥ 0.6.2; for most enterprise stacks this is niche software, making this a conditional urgent patch rather than a universal action.
- SOC/IR — Learn: Active fund-drain exploitation across six blockchains signals a real threat actor capability against Cosmos EVM infrastructure, but the summary provides no IOCs, ATT&CK-mappable TTPs, or detection artifacts; file for context and watch for follow-on threat intel with actionable indicators.
- Leader — Plan: Assess whether your organization has custody, treasury, or operational exposure to any of the six affected Cosmos EVM chains, and request incident attestation and remediation status from relevant blockchain service providers this quarter.
- Engineer — Learn: No patch or config action required, but this technique — using decentralized blockchain services instead of traditional C2 — changes how defenders should think about network egress controls and ransomware resilience. Review whether your environment restricts outbound connections to blockchain RPCs and the Session messaging network.
- SOC/IR — Plan: DeadLock’s use of Polygon smart contracts and Session protocol for victim comms creates a new detection surface; build or tune detections for Session network traffic and Polygon RPC calls originating from endpoints and servers, and add this TTP to ransomware hunt playbooks this quarter.
- Leader — Learn: Ransomware groups adopting decentralized infrastructure reduces the effectiveness of traditional law-enforcement takedowns, which has implications for incident response assumptions and cyber-insurance negotiations around extortion scenarios — useful context for the next IR retainer or insurance renewal discussion.
- Engineer — Learn: No patch or configuration action available; the technique signals that traditional domain-takedown mitigations matter less for this operator, which is worth factoring into egress-filtering and backup-isolation architecture reviews.
- SOC/IR — Learn: No IOCs or ATT&CK-mapped TTPs are available to hunt or detect; worth absorbing for IR playbook updates, as blockchain-backed C2 limits the value of expecting law-enforcement takedown to cut off active intrusions.
- Leader — Learn: Useful framing for board-level ransomware risk discussions: blockchain-anchored infrastructure reduces the effectiveness of law-enforcement disruption as a risk mitigant, which may affect how resilient response plans need to be.
- Engineer — Learn: If you expose Solana JSON-RPC or gRPC dev endpoints (e.g., surfpool) on public interfaces, audit firewall rules to ensure they are not internet-reachable; no active exploitation or PoC reported.
- SOC/IR — Learn: Awareness item: opportunistic scans targeting Solana dev endpoints are occurring, but no IOCs, TTPs, or confirmed exploitation are provided to act on.
- Leader — Skip
- Engineer — Learn: Blockchain-based C2 is an emerging evasion technique that may bypass traditional domain-blocking controls; no patch or configuration action required, but architects should consider that blocking Polygon RPC endpoints could disrupt legitimate Web3 tooling.
- SOC/IR — Plan: Build or tune detections for outbound calls to Polygon RPC endpoints (e.g., polygon-rpc.com) from non-Web3 workloads, and develop hunting queries for processes that query smart contract ABI methods as a C2 channel.
- Leader — Learn: Blockchain-anchored C2 represents a structural evasion of perimeter controls; useful context for future investments in DNS/network monitoring that can handle decentralized infrastructure, but no immediate leadership action required.
- Engineer — Act: Two named malicious packages — ‘bianira-ui’ and ‘fluid-type-ui’ — are trojanized with active C2 capability; audit all dependency trees and lock files for these packages and remove them immediately if found.
- SOC/IR — Plan: NullReceiver is a novel dead-drop resolver technique that hides C2 IPs inside empty Ethereum transfer destinations, making traditional blocklist-based detections ineffective; build or tune detections for unusual outbound Ethereum RPC calls originating from build pipelines or developer endpoints this quarter.
- Leader — Learn: Attackers are using blockchain infrastructure to evade C2 detection in software supply-chain attacks — a technique evolution worth including in risk-posture discussions, but no immediate leadership action is required given the limited scope and absence of a major corroborated campaign.