<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>C2-Infrastructure on CuraSec</title><link>https://curasec.metacog.co.kr/tags/c2-infrastructure/</link><description>Recent content in C2-Infrastructure on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 11 Aug 2026 11:54:43 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/c2-infrastructure/index.xml" rel="self" type="application/rss+xml"/><item><title>Aeternum Botnet Uses Polygon Blockchain for Decentralized C2</title><link>https://curasec.metacog.co.kr/insights/2026-08-11-the-permanent-threat-analyzing-aeternum-s-blockchain-based-c/</link><pubDate>Tue, 11 Aug 2026 11:54:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-11-the-permanent-threat-analyzing-aeternum-s-blockchain-based-c/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Blockchain-based C2 is an emerging evasion technique that may bypass traditional domain-blocking controls; no patch or configuration action required, but architects should consider that blocking Polygon RPC endpoints could disrupt legitimate Web3 tooling.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Build or tune detections for outbound calls to Polygon RPC endpoints (e.g., polygon-rpc.com) from non-Web3 workloads, and develop hunting queries for processes that query smart contract ABI methods as a C2 channel.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Blockchain-anchored C2 represents a structural evasion of perimeter controls; useful context for future investments in DNS/network monitoring that can handle decentralized infrastructure, but no immediate leadership action required.&lt;/li>
&lt;/ul></description></item><item><title>Dysphoria IoT Botnet Adopts Blockchain C2 After JackSkid Takedown</title><link>https://curasec.metacog.co.kr/insights/2026-07-28-dysphoria-iot-botnet-adds-blockchain-c2-and-victim-relays-af/</link><pubDate>Tue, 28 Jul 2026 13:01:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-28-dysphoria-iot-botnet-adds-blockchain-c2-and-victim-relays-af/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Blockchain-based C2 and peer-relay architecture represent an evasion technique relevant to defenders running IoT-adjacent infrastructure, but there are no specific CVEs, affected products, or actionable mitigations named here.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> The shift to blockchain name services and victim-device relays changes the detection model for this botnet family; build or tune detections for anomalous outbound connections to blockchain resolvers and unexpected device-to-device relay traffic in your estate.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Useful context on botnet resilience trends following law-enforcement disruptions, but no immediate vendor exposure or board-level risk event is indicated here.&lt;/li>
&lt;/ul></description></item></channel></rss>