As cited
Copy frozen at (site build).
threat intel
PHANTOMPULSE: anatomy of a hijackable blockchain-C2 RAT
Elastic Security Labs analyzed PHANTOMPULSE, a remote access trojan (RAT) used by intrusion set REF6598 that resolves its command and control (C2) infrastructure through Ethereum blockchain transactions, implements three process injection techniques, and bypasses endpoint defenses including User Account Control (UAC), AMSI, Windows Defender Language Protection (WLDP), and Event Tracing for Windows (ETW) using a shared hardware breakpoint primitive. The malware exhibits strong fingerprints of artificial intelligence (AI)-assisted development, including structured step numbering, verbose diagnostic output, and function-tracing patterns typical of large language model (LLM) code generation. The analysis identified a critical weakness: the blockchain C2 resolver lacks sender verification, allowing defenders to override the C2 address by posting a single transaction.
Why it matters: Windows defenders need to understand that this implant uses blockchain for C2 resilience and employs multiple defense-evasion techniques simultaneously; the lack of sender verification on the blockchain resolver creates an immediate sinkhole opportunity for incident responders.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
PHANTOMPULSE: anatomy of a hijackable blockchain-C2 RAT
Elastic Security Labs analyzed PHANTOMPULSE, a remote access trojan (RAT) used by intrusion set REF6598 that resolves its command and control (C2) infrastructure through Ethereum blockchain transactions, implements three process injection techniques, and bypasses endpoint defenses including User Account Control (UAC), AMSI, Windows Defender Language Protection (WLDP), and Event Tracing for Windows (ETW) using a shared hardware breakpoint primitive. The malware exhibits strong fingerprints of artificial intelligence (AI)-assisted development, including structured step numbering, verbose diagnostic output, and function-tracing patterns typical of large language model (LLM) code generation. The analysis identified a critical weakness: the blockchain C2 resolver lacks sender verification, allowing defenders to override the C2 address by posting a single transaction.
Why it matters: Windows defenders need to understand that this implant uses blockchain for C2 resilience and employs multiple defense-evasion techniques simultaneously; the lack of sender verification on the blockchain resolver creates an immediate sinkhole opportunity for incident responders.
- Source published
- First seen by Cybersecurity Tracker