Potential EtherHiding C2 via Curl JSON-RPC Request

Detects when curl or nscurl is spawned by a shell or osascript to make a JSON-RPC request to a blockchain endpoint for command and control purposes. Adversaries may leverage blockchain smart contracts as a covert C2 channel to retrieve commands or payload staging information, as observed in ClickFix campaigns.

Elastic rule (View on GitHub)

  1[metadata]
  2creation_date = "2026/09/08"
  3integration = ["endpoint"]
  4maturity = "production"
  5updated_date = "2026/09/18"
  6
  7[rule]
  8author = ["Elastic"]
  9description = """
 10Detects when curl or nscurl is spawned by a shell or osascript to make a JSON-RPC request to a blockchain
 11endpoint for command and control purposes. Adversaries may leverage blockchain smart contracts as a covert
 12C2 channel to retrieve commands or payload staging information, as observed in ClickFix campaigns.
 13"""
 14from = "now-9m"
 15index = ["logs-endpoint.events.process-*"]
 16language = "eql"
 17license = "Elastic License v2"
 18name = "Potential EtherHiding C2 via Curl JSON-RPC Request"
 19references = [
 20    "https://notes.netbytesec.com/2026/08/anatomy-of-macos-clickfix-crimekit-that.html",
 21    "https://cloud.google.com/blog/topics/threat-intelligence/dprk-adopts-etherhiding",
 22    "https://cloud.google.com/blog/topics/threat-intelligence/unc5142-etherhiding-distribute-malware",
 23
 24]
 25risk_score = 73
 26rule_id = "54285d96-2b7c-4345-890e-3c40e173f099"
 27severity = "high"
 28tags = [
 29    "Domain: Endpoint",
 30    "OS: macOS",
 31    "Use Case: Threat Detection",
 32    "Tactic: Command and Control",
 33    "Tactic: Execution",
 34    "Data Source: Elastic Defend",
 35    "Resources: Investigation Guide",
 36    "Rule Type: Event Correlation (EQL)",
 37    "Platform: macOS",
 38]
 39timestamp_override = "event.ingested"
 40type = "eql"
 41
 42query = '''
 43process where host.os.type == "macos" and event.type == "start" and event.action == "exec" and
 44  process.name in ("curl", "nscurl") and
 45  process.parent.name in ("osascript", "bash", "sh", "zsh") and
 46  process.command_line like~ ("*eth_call*", "*\"jsonrpc\"*")
 47'''
 48
 49note = """## Triage and analysis
 50
 51### Investigating Potential EtherHiding C2 via Curl JSON-RPC Request
 52
 53EtherHiding is a command and control technique in which threat actors store malicious configuration, commands,
 54or payload URLs inside smart contract data on public blockchains. Because the blockchain is immutable and the
 55RPC endpoints are legitimate public infrastructure, this provides a takedown-resistant C2 channel. On macOS,
 56ClickFix-delivered loaders have been observed reading contract data by spawning curl from a shell or osascript
 57with a raw JSON-RPC eth_call request body.
 58
 59### Possible investigation steps
 60
 61- Review process.command_line to identify the destination RPC endpoint, the contract address in the eth_call
 62  parameters, and the method selector.
 63- Examine the parent process chain (process.parent.command_line, effective parent) to determine how the shell
 64  or osascript was launched — interactive terminal, LaunchAgent, or another persistence mechanism.
 65- Search the same host for follow-on network connections shortly after this event; EtherHiding reads are
 66  typically followed by a connection to the decoded C2 host.
 67- Check for recent LaunchAgent or LaunchDaemon plist creation on the host, which commonly accompanies this
 68  activity as persistence.
 69- Search the contract address against threat intelligence sources to identify the associated campaign.
 70- Pivot fleet-wide on the destination RPC domain and any decoded C2 domains to identify additional hosts.
 71
 72### False positive analysis
 73
 74- Web3 developers may test contract calls with curl against RPC endpoints. Verify whether the user has a
 75  legitimate blockchain development role and whether the parent context (terminal session vs. persistence
 76  item) matches interactive development work.
 77- CI or build scripts that query chain state via curl could match. Confirm with the owning team and consider
 78  excluding specific parent scripts or hosts.
 79
 80### Response and remediation
 81
 82- Isolate the affected host to interrupt the C2 channel.
 83- Terminate the parent shell or osascript process tree.
 84- Identify and remove any associated persistence (LaunchAgents/LaunchDaemons) and decoded payloads.
 85- Block decoded C2 domains identified from the contract data; note that blocking public RPC aggregators may
 86  impact legitimate use and should be a risk-based decision.
 87- Rotate credentials accessible from the host and review for evidence of data theft.
 88- Escalate for full incident response if the activity chains from a ClickFix or social engineering delivery.
 89"""
 90
 91[[rule.threat]]
 92framework = "MITRE ATT&CK"
 93
 94[[rule.threat.technique]]
 95id = "T1102"
 96name = "Web Service"
 97reference = "https://attack.mitre.org/techniques/T1102/"
 98
 99[[rule.threat.technique.subtechnique]]
100id = "T1102.001"
101name = "Dead Drop Resolver"
102reference = "https://attack.mitre.org/techniques/T1102/001/"
103
104[[rule.threat.technique.subtechnique]]
105id = "T1102.002"
106name = "Bidirectional Communication"
107reference = "https://attack.mitre.org/techniques/T1102/002/"
108
109[rule.threat.tactic]
110id = "TA0011"
111name = "Command and Control"
112reference = "https://attack.mitre.org/tactics/TA0011/"
113
114[[rule.threat]]
115framework = "MITRE ATT&CK"
116
117[[rule.threat.technique]]
118id = "T1059"
119name = "Command and Scripting Interpreter"
120reference = "https://attack.mitre.org/techniques/T1059/"
121
122[[rule.threat.technique.subtechnique]]
123id = "T1059.002"
124name = "AppleScript"
125reference = "https://attack.mitre.org/techniques/T1059/002/"
126
127[[rule.threat.technique.subtechnique]]
128id = "T1059.004"
129name = "Unix Shell"
130reference = "https://attack.mitre.org/techniques/T1059/004/"
131
132[rule.threat.tactic]
133id = "TA0002"
134name = "Execution"
135reference = "https://attack.mitre.org/tactics/TA0002/"```

Triage and analysis

Investigating Potential EtherHiding C2 via Curl JSON-RPC Request

EtherHiding is a command and control technique in which threat actors store malicious configuration, commands, or payload URLs inside smart contract data on public blockchains. Because the blockchain is immutable and the RPC endpoints are legitimate public infrastructure, this provides a takedown-resistant C2 channel. On macOS, ClickFix-delivered loaders have been observed reading contract data by spawning curl from a shell or osascript with a raw JSON-RPC eth_call request body.

Possible investigation steps

  • Review process.command_line to identify the destination RPC endpoint, the contract address in the eth_call parameters, and the method selector.
  • Examine the parent process chain (process.parent.command_line, effective parent) to determine how the shell or osascript was launched — interactive terminal, LaunchAgent, or another persistence mechanism.
  • Search the same host for follow-on network connections shortly after this event; EtherHiding reads are typically followed by a connection to the decoded C2 host.
  • Check for recent LaunchAgent or LaunchDaemon plist creation on the host, which commonly accompanies this activity as persistence.
  • Search the contract address against threat intelligence sources to identify the associated campaign.
  • Pivot fleet-wide on the destination RPC domain and any decoded C2 domains to identify additional hosts.

False positive analysis

  • Web3 developers may test contract calls with curl against RPC endpoints. Verify whether the user has a legitimate blockchain development role and whether the parent context (terminal session vs. persistence item) matches interactive development work.
  • CI or build scripts that query chain state via curl could match. Confirm with the owning team and consider excluding specific parent scripts or hosts.

Response and remediation

  • Isolate the affected host to interrupt the C2 channel.
  • Terminate the parent shell or osascript process tree.
  • Identify and remove any associated persistence (LaunchAgents/LaunchDaemons) and decoded payloads.
  • Block decoded C2 domains identified from the contract data; note that blocking public RPC aggregators may impact legitimate use and should be a risk-based decision.
  • Rotate credentials accessible from the host and review for evidence of data theft.
  • Escalate for full incident response if the activity chains from a ClickFix or social engineering delivery.

References

Related rules

to-top