새로운 트로이 목마 npm 패키지가 이더리움 주소에 숨겨진 C2 서버 IP를 감지합니다.
사이버 보안 연구자들은 EtherHiding 기반 C2 기술이 발전하여, 완전히 비어 있는 이더리움 전송의 목적지 주소에 C2 서버 IP를 숨기는 방법이 있다고 경고했습니다. 새로운 방식인 'NullReceiver'는 트로이 목마 npm 패키지인 'bianira-ui'와 'fluid-type-ui'에서 관찰되었습니다. 이 기술은 악성 코드의 통신을 은폐하는 데 사용됩니다.
New trojanized npm packages hide C2 server IPs in Ethereum addresses.
Cybersecurity researchers have flagged an evolution of the EtherHiding C2 technique that hides the C2 server IP address inside a dummy destination address of a zero-value Ethereum transfer. The new approach, dubbed 'NullReceiver,' was observed in trojanized npm packages 'bianira-ui' and 'fluid-type-ui.' This technique is used to obscure communication of malicious code.