logoalt Hacker News

kachapopopowlast Sunday at 7:26 PM3 repliesview on HN

speaking of command and control servers, the best one you can get at the moment is to just to use crypto currencies, plenty of available nodes to auto discover or just rely on explorers to query your own wallet, deposit address can encode quite a bit of information since it's a pretty long address and definitely has enough bytes to encode commands


Replies

mattwieselast Sunday at 7:41 PM

I want to thank you and the other user (hobofan) for pointing out the use of crypto currencies as C2s. I do bioinformatics for a living, not infosec, so that's another fun little rabbit hole for me to go on...

show 1 reply
sneaklast Sunday at 7:29 PM

Many networks block non-http/s traffic.

show 1 reply
monerozcashlast Monday at 2:40 PM

There are much lighter alternatives though, why would you want to bother with cryptocurrencies when you could just use DHT?

I mean, even just shipping a Tor client embedded in your malware seems like a much better idea.

>just rely on explorers to query your own wallet

This kind of defeats the point, you get exactly 0 censorship resistance like this.

show 1 reply