<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>C2-Evasion on CuraSec</title><link>https://curasec.metacog.co.kr/tags/c2-evasion/</link><description>Recent content in C2-Evasion on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 12 Aug 2026 11:57:00 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/c2-evasion/index.xml" rel="self" type="application/rss+xml"/><item><title>DeadLock Ransomware Uses Polygon Blockchain to Harden Extortion Infra</title><link>https://curasec.metacog.co.kr/insights/2026-08-12-deadlock-ransomware-uses-polygon-smart-contracts-to-make-ext/</link><pubDate>Wed, 12 Aug 2026 11:57:00 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-12-deadlock-ransomware-uses-polygon-smart-contracts-to-make-ext/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> No patch or config action required, but this technique — using decentralized blockchain services instead of traditional C2 — changes how defenders should think about network egress controls and ransomware resilience. Review whether your environment restricts outbound connections to blockchain RPCs and the Session messaging network.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> DeadLock&amp;rsquo;s use of Polygon smart contracts and Session protocol for victim comms creates a new detection surface; build or tune detections for Session network traffic and Polygon RPC calls originating from endpoints and servers, and add this TTP to ransomware hunt playbooks this quarter.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Ransomware groups adopting decentralized infrastructure reduces the effectiveness of traditional law-enforcement takedowns, which has implications for incident response assumptions and cyber-insurance negotiations around extortion scenarios — useful context for the next IR retainer or insurance renewal discussion.&lt;/li>
&lt;/ul></description></item><item><title>Kimwolf v7 Botnet Uses Ethereum ENS for C2 and Tor Backup Routing</title><link>https://curasec.metacog.co.kr/insights/2026-08-11-kimwolf-v7-an-evolution-of-the-kimwolf-botnet/</link><pubDate>Tue, 11 Aug 2026 11:54:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-11-kimwolf-v7-an-evolution-of-the-kimwolf-botnet/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Kimwolf v7&amp;rsquo;s use of Ethereum Name Service for C2 resolution and Tor as a fallback is a novel evasion pattern worth incorporating into threat models for IoT/edge assets, but no patch or config change applies to typical cloud/AppSec environments.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> The ENS-based C2 resolution and Tor backup routing introduce detection gaps in traditional domain-block and DNS monitoring approaches; plan detection coverage for anomalous Ethereum ENS lookups and unexpected Tor traffic from IoT segments this quarter.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Trojanized npm Packages Use Blockchain to Hide C2 IP (NullReceiver)</title><link>https://curasec.metacog.co.kr/insights/2026-08-06-trojanized-npm-packages-employ-nullreceiver-tactic-to-decode/</link><pubDate>Thu, 06 Aug 2026 13:03:19 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-06-trojanized-npm-packages-employ-nullreceiver-tactic-to-decode/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Two named malicious packages — &amp;lsquo;bianira-ui&amp;rsquo; and &amp;lsquo;fluid-type-ui&amp;rsquo; — are trojanized with active C2 capability; audit all dependency trees and lock files for these packages and remove them immediately if found.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> NullReceiver is a novel dead-drop resolver technique that hides C2 IPs inside empty Ethereum transfer destinations, making traditional blocklist-based detections ineffective; build or tune detections for unusual outbound Ethereum RPC calls originating from build pipelines or developer endpoints this quarter.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Attackers are using blockchain infrastructure to evade C2 detection in software supply-chain attacks — a technique evolution worth including in risk-posture discussions, but no immediate leadership action is required given the limited scope and absence of a major corroborated campaign.&lt;/li>
&lt;/ul></description></item><item><title>Chaos Ransomware msaRAT Routes C2 via Headless Chrome/Edge</title><link>https://curasec.metacog.co.kr/insights/2026-07-24-chaos-ransomware-uses-msarat-to-route-c2-traffic-through-hea/</link><pubDate>Fri, 24 Jul 2026 12:43:46 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-24-chaos-ransomware-uses-msarat-to-route-c2-traffic-through-hea/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> No patchable vulnerability here — this is a C2 evasion technique that bypasses outbound network controls by abusing the local browser. Worth understanding when designing network egress policy and process-spawn allow-lists, but no immediate system change required.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Cisco Talos documented a pre-ransomware implant with a distinctive behavioral fingerprint: it binds only to 127.0.0.1 and spawns Chrome or Edge headlessly to carry C2 traffic — invisible to traditional network detection. Hunt for unexpected headless browser processes with anomalous parent processes and tune EDR rules to flag this spawn chain on Windows endpoints.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Chaos ransomware has deployed a novel evasion capability that makes their pre-encryption activity harder to detect; worth flagging to the security team to ensure detection coverage, but no executive action or vendor exposure check required at this stage.&lt;/li>
&lt;/ul></description></item><item><title>msaRAT malware routes C2 through Chrome/Edge browsers</title><link>https://curasec.metacog.co.kr/insights/2026-07-23-new-msarat-malware-uses-chrome-edge-browsers-to-route-c2-tra/</link><pubDate>Thu, 23 Jul 2026 12:47:45 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-23-new-msarat-malware-uses-chrome-edge-browsers-to-route-c2-tra/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Novel C2 technique using legitimate browser processes to blend malicious traffic — no KEV, PoC, or EPSS data means no patch action today, but informs browser isolation and process-spawn monitoring design decisions.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Build or tune detections for unusual network egress spawned from Chrome/Edge processes outside of normal user activity; no IOCs are published in this item yet, but the Chaos gang&amp;rsquo;s adoption of browser-proxied C2 warrants a detection gap assessment this quarter.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>