Several Cyber Attacks Observed Leveraging IPFS Decentralized Network

Share:

A number of phishing campaigns are leveraging the decentralized Interplanetary Filesystem (IPFS) network to host malware, phishing kit infrastructure, and facilitate other attacks.

“Multiple malware families are currently being hosted within IPFS and retrieved during the initial stages of malware attacks,” Cisco Talos researcher Edmund Brumaghin said in an analysis shared with The Hacker News.

The research mirrors similar findings from Trustwave SpiderLabs in July 2022, which found more than 3,000 emails containing IPFS phishing URLs as an attack vector, calling IPFS the new “hotbed” for hosting phishing sites.

IPFS as a technology is both resilient to censorship and takedowns, making it a double-edged sword. Underlying it is a peer-to-peer (P2P) network which replicates content across all participating nodes so that even if content is removed from one machine, requests for the resources can still be served via other systems.

This also makes it ripe for abuse by bad actors looking to host malware that can resist law enforcement attempts at disrupting their attack infrastructure, like seen in the case of Emotet last year.

“IPFS is currently being abused by a variety of threat actors who are using it to host malicious contents as part of phishing and malware distribution campaigns,” Brumaghin previously told The Hacker News in August 2022.

This includes Dark Utilities, a command-and-control (C2) framework that’s advertised as a way for adversaries to avail remote system access, DDoS capabilities, and cryptocurrency mining, with the payload binaries provided by the platform hosted in IPFS.

Bild10 3

Furthermore, IPFS has been put to use to serve rogue landing pages as part of phishing campaigns orchestrated to steal credentials and distribute a wide range of malware comprising Agent Tesla, reverse shells, data wiper, and an information stealer called Hannabi Grabber.

In one malspam delivery chain detailed by Talos, an email purporting to be from a Turkish financial institution urged the recipient to open a ZIP file attachment that, when launched, worked as a downloader to retrieve an obfuscated version of Agent Tesla hosted within the IPFS network.

 

The destructive malware, for its part, takes the form of a batch file that deletes backups and recursively purges all directory contents. Hannabi Grabber is a Python-based malware that gathers sensitive information from the infected host, such as browser data and screenshots, and transmits it via a Discord Webhook.

The latest development points to the growing use by attackers of legitimate offerings such as Discord, Slack, Telegram, Dropbox, Google Drive, AWS, and several others to host malicious content or to direct users to it, making phishing one of the lucrative primary initial access vectors.

“We expect this activity to continue to increase as more threat actors recognize that IPFS can be used to facilitate bulletproof hosting, is resilient against content moderation and law enforcement activities, and introduces problems for organizations attempting to detect and defend against attacks that may leverage the IPFS network,” Brumaghin said.

https://thehackernews.com/2022/11/several-cyber-attacks-observed.html?

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
2:57 am, Jul 9, 2025
weather icon 14°C
L: 12° | H: 16°
few clouds
Humidity: 73 %
Pressure: 1020 mb
Wind: 2 mph NW
Wind Gust: 3 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 14%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:54 am
Sunset: 9:16 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
12° | 16°°C 0.03 mm 3% 7 mph 74 % 1022 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
18° | 29°°C 0 mm 0% 8 mph 71 % 1023 mb 0 mm/h
Fri Jul 11 10:00 pm
weather icon
19° | 29°°C 0 mm 0% 8 mph 62 % 1022 mb 0 mm/h
Sat Jul 12 10:00 pm
weather icon
19° | 30°°C 0 mm 0% 10 mph 63 % 1019 mb 0 mm/h
Sun Jul 13 10:00 pm
weather icon
18° | 31°°C 0 mm 0% 9 mph 70 % 1018 mb 0 mm/h
Today 4:00 am
weather icon
14° | 14°°C 0 mm 0% 2 mph 74 % 1020 mb 0 mm/h
Today 7:00 am
weather icon
15° | 16°°C 0 mm 0% 3 mph 67 % 1020 mb 0 mm/h
Today 10:00 am
weather icon
19° | 22°°C 0 mm 0% 4 mph 54 % 1021 mb 0 mm/h
Today 1:00 pm
weather icon
24° | 24°°C 0 mm 0% 6 mph 49 % 1021 mb 0 mm/h
Today 4:00 pm
weather icon
26° | 26°°C 0.03 mm 3% 7 mph 42 % 1021 mb 0 mm/h
Today 7:00 pm
weather icon
25° | 25°°C 0 mm 0% 3 mph 43 % 1021 mb 0 mm/h
Today 10:00 pm
weather icon
22° | 22°°C 0 mm 0% 3 mph 57 % 1022 mb 0 mm/h
Tomorrow 1:00 am
weather icon
20° | 20°°C 0 mm 0% 3 mph 62 % 1022 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,776.00
0.79%
Ethereum(ETH)
€2,220.58
2.89%
Tether(USDT)
€0.85
0.01%
XRP(XRP)
€1.97
2.06%
Solana(SOL)
€129.15
1.53%
USDC(USDC)
€0.85
0.01%
Dogecoin(DOGE)
€0.145230
2.09%
Shiba Inu(SHIB)
€0.000010
1.72%
Pepe(PEPE)
€0.000009
2.27%
Scroll to Top