New Orchard Botnet Generates DGA Using Bitcoin Transaction Information

Summary: 360 Netlab uncovers a botnet that leverages Bitcoin transactions to generate DGA domains, making detection significantly more challenging.

360 Netlab describes Orchard as an interesting evolution within the botnet ecosystem: rather than relying solely on predictable time-based algorithms for DGA domain generation, it introduces a dynamic and external element—Bitcoin transactions—as a source of entropy.

This approach complicates traditional defenses significantly. While traditional DGA domains allow analysts to anticipate patterns and block them before they are utilized, using blockchain data introduces an additional layer of unpredictability that diminishes the effectiveness of classical detection techniques.

Orchard's hybrid model, which combines hardcoded domains with dynamic generation, reinforces its resilience against interruptions. Although its functional capabilities—information gathering, command execution, and payload delivery—are not new, the way it protects its C2 infrastructure is.

In total, this case highlights how attackers are exploring open and decentralized data sources to enhance evasion, raising the complexity level for defensive teams.

Key facts

  • Orchard is a botnet that uses DGA with information from Bitcoin transactions
  • Three versions of Orchard have been identified since February 2021
  • The latest version of Orchard incorporates information from Bitcoin transactions to generate separate DGA domains

Why it matters

The use of blockchain as a base for DGA introduces a new challenge in detecting botnets and necessitates rethinking traditional defensive strategies.

Embedded content for: New Orchard Botnet Generates DGA Using Bitcoin Transaction Information