RPC Nodes
Observable Types: domain
Description
Etherhiding has become a common technique for malware second stages. While this is effective for dynamically cycling C2 addresses and third stages, it creates a hard reliance on cryptocurrency RPC node APIs to access the wallets and smart contracts that provide that dynamic information. As a result, blocking those RPC endpoints is a highly effective defensive strategy. This list comprises most known RPC nodes, and certainly the most popular.
Blocking these domains neutralizes multiple classes of current malware before damaging impact occurs.
Techniques
References
- https://ifin-intel.org/blog/etherhiding
- https://cloud.google.com/blog/topics/threat-intelligence/dprk-adopts-etherhiding
- https://www.netskope.com/blog/openclaw-trap-ai-assisted-lure-factory-targets-developers-gamers
- https://www.microsoft.com/en-us/security/blog/2026/07/16/acr-stealer-two-observed-intrusion-chains-amid-increased-threat-activity/
- https://labs.guard.io/etherhiding-hiding-web2-malicious-code-in-web3-smart-contracts-65ea78efad16