A cybercriminal campaign active since November 2025 has been caught storing its command-and-control (C2) instructions inside smart contracts on the Polygon blockchain rather than hardcoding server addresses into malware, according to new research from GuidePoint Security.
The technique, known as EtherHiding, lets attackers rotate infrastructure instantly and cheaply while making takedown efforts largely futile.
The malware can retrieve commands or configuration data from the blockchain instead of relying on traditional servers. Because blockchain data is decentralized and hard to modify or remove, this technique helps attackers maintain a more resilient C2 infrastructure.
Malware Hides C2 Servers Inside Polygon Smart Contracts
GuidePoint’s DFIR team stumbled onto the campaign while investigating a routine Business Email Compromise case.
A single smart contract address became the thread that unraveled an entire operation: two operator wallets, 15 smart contracts deployed across six waves over seven months, three previously unreported C2 domains, and at least 31 compromised legitimate business websites spanning multiple countries and industries.
The infection chain follows a familiar “ClickFix” or FakeCaptcha pattern. Victims land on compromised sites via Bing or Google, encounter a fake human-verification overlay, and are tricked into pasting a malicious command into the Windows Run dialog.
That command creates a scheduled task named “Enter” that retries every 60 seconds until it successfully fetches a dropper, which then plants a PowerShell backdoor and a registry-based persistence mechanism.

Instead of contacting a fixed server, the backdoor queries a Polygon smart contract through nine hardcoded RPC endpoints, asking essentially: “where do I connect now?” The encrypted response reveals the live C2 domain.
Because blockchain writes are permanent and distributed, a single low-cost transaction can redirect every infected machine simultaneously, eliminating the single point of failure that traditional domain or IP blocking depends on.
That resilience, however, cuts both ways. Every contract update is permanently logged on a public ledger, and researchers used that exact transparency to trace one exposed contract back to an entire wallet history of 12 additional “silent” contracts the attackers deliberately built without event logs, specifically to resist this style of forensic pivoting.
What began as a general-purpose backdoor has escalated. GuidePoint observed it deploying a fake browser extension functioning as a real-time banking trojan, targeting roughly 479 financial and cryptocurrency domains with keylogging, screen capture, and credential theft capabilities.
Ironically, one campaign server onemm[.]net wasn’t hidden behind Cloudflare like the rest of the infrastructure, exposing an IP address running seven actively exploited vulnerabilities, including the “Looney Tunables” glibc flaw (CVE-2023-4911) and the OpenSSH “regreSSHion” bug (CVE-2024-6387).
As of publication, three C2 domains hivinest[.]online, insinght[.]site, and 3262d48df5d75e34[.]shop remain active, and several compromised sites continue serving the malicious script.

Domain blocking is inherently reactive against this architecture. Delivery domains are single-session and expire within a day, while the underlying smart contracts persist on Polygon indefinitely.
GuidePoint recommends defenders shift focus toward behavioral detection alerting on the “Enter” scheduled task, registry key PersonalizedUpdates, outbound Polygon RPC traffic, and MachineGuid reads rather than chasing an endless rotation of domains.
EtherHiding’s criminal debut in 2023 was followed by adoption from North Korea’s UNC5342 and Iran-linked MuddyWater. This campaign’s use of Polygon, rather than the previously documented Binance Smart Chain, signals the technique’s continued spread through the broader cybercrime ecosystem and a defensive challenge that traditional IOC-based blocking simply cannot keep pace with.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.