Several Cyber Attacks Observed Leveraging IPFS Decentralized Network

Teilen:

A number of phishing campaigns are leveraging the decentralized Interplanetary Filesystem (IPFS) network to host malware, phishing kit infrastructure, and facilitate other attacks.

“Multiple malware families are currently being hosted within IPFS and retrieved during the initial stages of malware attacks,” Cisco Talos researcher Edmund Brumaghin said in an analysis shared with The Hacker News.

The research mirrors similar findings from Trustwave SpiderLabs in July 2022, which found more than 3,000 emails containing IPFS phishing URLs as an attack vector, calling IPFS the new “hotbed” for hosting phishing sites.

IPFS as a technology is both resilient to censorship and takedowns, making it a double-edged sword. Underlying it is a peer-to-peer (P2P) network which replicates content across all participating nodes so that even if content is removed from one machine, requests for the resources can still be served via other systems.

This also makes it ripe for abuse by bad actors looking to host malware that can resist law enforcement attempts at disrupting their attack infrastructure, like seen in the case of Emotet last year.

“IPFS is currently being abused by a variety of threat actors who are using it to host malicious contents as part of phishing and malware distribution campaigns,” Brumaghin previously told The Hacker News in August 2022.

This includes Dark Utilities, a command-and-control (C2) framework that’s advertised as a way for adversaries to avail remote system access, DDoS capabilities, and cryptocurrency mining, with the payload binaries provided by the platform hosted in IPFS.

Bild10 3

Furthermore, IPFS has been put to use to serve rogue landing pages as part of phishing campaigns orchestrated to steal credentials and distribute a wide range of malware comprising Agent Tesla, reverse shells, data wiper, and an information stealer called Hannabi Grabber.

In one malspam delivery chain detailed by Talos, an email purporting to be from a Turkish financial institution urged the recipient to open a ZIP file attachment that, when launched, worked as a downloader to retrieve an obfuscated version of Agent Tesla hosted within the IPFS network.

 

The destructive malware, for its part, takes the form of a batch file that deletes backups and recursively purges all directory contents. Hannabi Grabber is a Python-based malware that gathers sensitive information from the infected host, such as browser data and screenshots, and transmits it via a Discord Webhook.

The latest development points to the growing use by attackers of legitimate offerings such as Discord, Slack, Telegram, Dropbox, Google Drive, AWS, and several others to host malicious content or to direct users to it, making phishing one of the lucrative primary initial access vectors.

“We expect this activity to continue to increase as more threat actors recognize that IPFS can be used to facilitate bulletproof hosting, is resilient against content moderation and law enforcement activities, and introduces problems for organizations attempting to detect and defend against attacks that may leverage the IPFS network,” Brumaghin said.

https://thehackernews.com/2022/11/several-cyber-attacks-observed.html?

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
3:21 am, Juli 9, 2025
Wetter-Symbol 13°C
L: 11° | H: 15°
wenige Wolken
Luftfeuchtigkeit: 74 %
Druck: 1020 mb
Wind: 2 mph NW
Windböe: 3 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 14%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:54 am
Sonnenuntergang: 9:16 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
11° | 15°°C 0.03 mm 3% 7 mph 75 % 1022 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
18° | 29°°C 0 mm 0% 8 mph 71 % 1023 mb 0 mm/h
Fr. Juli 11 10:00 pm
Wetter-Symbol
19° | 29°°C 0 mm 0% 8 mph 62 % 1022 mb 0 mm/h
Sa. Juli 12 10:00 pm
Wetter-Symbol
19° | 30°°C 0 mm 0% 10 mph 63 % 1019 mb 0 mm/h
So. Juli 13 10:00 pm
Wetter-Symbol
18° | 31°°C 0 mm 0% 9 mph 70 % 1018 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
13° | 13°°C 0 mm 0% 2 mph 75 % 1020 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
14° | 16°°C 0 mm 0% 3 mph 68 % 1020 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
19° | 22°°C 0 mm 0% 4 mph 55 % 1021 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 6 mph 49 % 1021 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
26° | 26°°C 0.03 mm 3% 7 mph 42 % 1021 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
25° | 25°°C 0 mm 0% 3 mph 43 % 1021 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
22° | 22°°C 0 mm 0% 3 mph 57 % 1022 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
20° | 20°°C 0 mm 0% 3 mph 62 % 1022 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,836.56
1.09%
Ethereum(ETH)
€2,224.48
3.19%
Fesseln(USDT)
€0.85
0.02%
XRP(XRP)
€1.97
2.61%
Solana(SOL)
€129.27
1.98%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.145708
2.64%
Shiba Inu(SHIB)
€0.000010
2.14%
Pepe(PEPE)
€0.000009
2.87%
Nach oben scrollen