EtherHiding: Blockchain-Based C2 Bootstrapping
discovered 2026-08-04C2 domain configuration stored in an Ethereum smart contract. Malware calls a read-only contract function via public RPC endpoints to retrieve active C2 domains. Censorship-resistant: no registrar or CDN can take down the configuration. Domain rotation via a single on-chain transaction. eth_call is free (no gas), unauthenticated, and traffic to public RPC providers is indistinguishable from legitimate Web3 application usage.