CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

PHANTOMPULSE: anatomy of a hijackable blockchain-C2 RAT

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 617

As cited

Copy frozen at (site build).

threat intel

PHANTOMPULSE: anatomy of a hijackable blockchain-C2 RAT

Elastic Security Labs analyzed PHANTOMPULSE, a remote access trojan (RAT) used by intrusion set REF6598 that resolves its command and control (C2) infrastructure through Ethereum blockchain transactions, implements three process injection techniques, and bypasses endpoint defenses including User Account Control (UAC), AMSI, Windows Defender Language Protection (WLDP), and Event Tracing for Windows (ETW) using a shared hardware breakpoint primitive. The malware exhibits strong fingerprints of artificial intelligence (AI)-assisted development, including structured step numbering, verbose diagnostic output, and function-tracing patterns typical of large language model (LLM) code generation. The analysis identified a critical weakness: the blockchain C2 resolver lacks sender verification, allowing defenders to override the C2 address by posting a single transaction.

Why it matters: Windows defenders need to understand that this implant uses blockchain for C2 resilience and employs multiple defense-evasion techniques simultaneously; the lack of sender verification on the blockchain resolver creates an immediate sinkhole opportunity for incident responders.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

PHANTOMPULSE: anatomy of a hijackable blockchain-C2 RAT

Elastic Security Labs analyzed PHANTOMPULSE, a remote access trojan (RAT) used by intrusion set REF6598 that resolves its command and control (C2) infrastructure through Ethereum blockchain transactions, implements three process injection techniques, and bypasses endpoint defenses including User Account Control (UAC), AMSI, Windows Defender Language Protection (WLDP), and Event Tracing for Windows (ETW) using a shared hardware breakpoint primitive. The malware exhibits strong fingerprints of artificial intelligence (AI)-assisted development, including structured step numbering, verbose diagnostic output, and function-tracing patterns typical of large language model (LLM) code generation. The analysis identified a critical weakness: the blockchain C2 resolver lacks sender verification, allowing defenders to override the C2 address by posting a single transaction.

Why it matters: Windows defenders need to understand that this implant uses blockchain for C2 resilience and employs multiple defense-evasion techniques simultaneously; the lack of sender verification on the blockchain resolver creates an immediate sinkhole opportunity for incident responders.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary