typetechniqueconfidencehighcreated2026-08-26updated2026-08-26c2-protocolc2exfiltrationmitre-attckevasion

ENS Ethereum C2 Resolution

Malware resolves its command-and-control endpoint by querying an Ethereum Name Service (ENS) text record via public Ethereum RPC endpoints. The ENS name itself may be hardcoded, derived from a seed, or decoded at runtime. This technique leverages legitimate public infrastructure (Ethereum mainnet RPC nodes) for C2 discovery, making blocking or takedown difficult without disabling all public Ethereum access.

Detection / Fingerprint

  • Hardcoded ENS Public Resolver contract address: 0x00000000000C2E074eC69A0dFb2997BA6C7d2e1e
  • Function signatures in strings: resolver(bytes32), text(bytes32,string)
  • Multiple hardcoded public Ethereum RPC endpoints (e.g., https://ethereum.publicnode.com, https://rpc.ankr.com/eth, https://eth-mainnet.public.blastapi.io)
  • JSON-RPC method strings: eth_blockNumber, eth_call
  • WebSocket or HTTPS outbound connections to Ethereum RPC nodes from a non-browser process

Implementation Patterns

Sample ec95bcf4 implements the full ENS resolution chain:

  1. Queries 15+ public RPC endpoints for redundancy
  2. Calls resolver(bytes32) on the ENS registry to get the resolver for the target name
  3. Calls text(bytes32,string) on the resolver to retrieve the C2 URL stored as an ENS text record
  4. Connects to the retrieved C2 via WebSocket-over-TLS (wss://)

The ENS name (bytes32 hash) and decryption key (JfR9z1!XMKjs#Ln0PqWe48@k2dFm7Yvz) are likely campaign-specific.

Defensive Countermeasures

  • Monitor non-browser processes making HTTPS requests to known public Ethereum RPC endpoints
  • Alert on eth_call payloads containing the ENS resolver address or text(bytes32,string) selector
  • DNS/URL filtering for *.eth names if observed in network telemetry
  • Network segmentation to block outbound Ethereum RPC access from endpoint workstations

Pages Where Observed