
One C2 kit. 30 customers. 2 governments
I was mapping the command-and-control infrastructure behind a state-linked intrusion set when the query came back and effectively ended the exercise I thought I was running.
The malware resolved its C2 address by reading a smart contract on a public blockchain. Public reporting described one contract. Working from the chain rather than the sample, I found that contract was one member of a family: Two dozen byte-identical contracts plus a set of variants, all emitting the same event, all stamped out by the same builder. Roughly 30 operator wallets were driving them.
Two of those wallets are plausibly state-aligned. The other 28 or so look like ordinary crimeware.
I went in looking for an acto...