RPC Nodes
Observable Types: domain
Description
Etherhiding has become a common technique for malware second stages. While this is effective for dynamically cycling C2 addresses and third stages, it creates a hard reliance on cryptocurrency RPC node APIs to access the wallets and smart contracts that provide that dynamic information. As a result, blocking those RPC endpoints is a highly effective defensive strategy. This list comprises most known RPC nodes, and certainly the most popular.
Blocking these domains neutralizes multiple classes of current malware before damaging impact occurs.
References
- https://ifin-intel.org/blog/etherhiding
- https://cloud.google.com/blog/topics/threat-intelligence/dprk-adopts-etherhiding
- https://www.netskope.com/blog/openclaw-trap-ai-assisted-lure-factory-targets-developers-gamers
- https://www.microsoft.com/en-us/security/blog/2026/07/16/acr-stealer-two-observed-intrusion-chains-amid-increased-threat-activity/
- https://labs.guard.io/etherhiding-hiding-web2-malicious-code-in-web3-smart-contracts-65ea78efad16