Skip to content

EtherRAT

EtherRAT is a cross-platform remote access trojan written in Node.js that has been used in Windows-domain intrusions, social-engineering campaigns, and broader post-compromise operations.

Profile source: Mallory opens in a new tab

EtherRAT

Family profile

EtherRAT is a cross-platform remote access trojan written in Node.js that has been used in Windows-domain intrusions, social-engineering campaigns, and broader post-compromise operations. It provides attackers with remote control of infected systems, including command execution, file manipulation, data theft, and long-term access. The malware is notable for using Ethereum blockchain infrastructure to resolve active command-and-control information, querying a smart contract rather than relying solely on hardcoded network locations. This design gives operators a resilient mechanism for rotating infrastructure and complicates disruption and tracking.

Observed Windows deployments show EtherRAT delivered through malicious MSI installers that bootstrap a Node.js runtime when needed, decrypt the embedded JavaScript implant, and establish persistence through user autorun mechanisms. In enterprise intrusions, operators have distributed those installers laterally using administrative shares, WMI, SMB, and remotely created scheduled tasks after obtaining privileged access. EtherRAT has also appeared in campaigns that abuse Microsoft Teams, where attackers impersonate IT support staff, persuade victims to grant remote control, and then use legitimate remote administration tools before executing the malware installer. Reporting also describes phishing lures, including employee-survey themed documents, as part of the initial social-engineering chain.

The malware has been associated with activity tied to an affiliate of the Gentlemen ransomware operation, where it formed part of a larger toolkit that included credential access, Active Directory collection, lateral movement, defense impairment, and fallback remote-access channels. Separate reporting indicates EtherRAT has been used beyond a single cluster and has appeared in campaigns linked to multiple threat actors. It has been observed targeting Windows environments directly and is described as capable of running on Linux and macOS as well, reflecting its Node.js-based portability.

Operationally, EtherRAT polls its controllers using web traffic patterns intended to blend in, and it can execute attacker-supplied JavaScript returned by the server, enabling flexible post-exploitation. Its role in intrusions is consistent with a persistent remote-access implant used to maintain footholds, support hands-on-keyboard activity, and facilitate follow-on actions including data theft and ransomware deployment.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 13, 2026
Last activity
Aug 13, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Leading locations

  • AU1

Leading providers

  • Microsoft Corporation1

Infrastructure traits

  • Hosting 1

Reported operators

Threat actors

6 named in public reporting
TheGentlemen

The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2

Unit 42

Threat actors are weaponizing something as ordinary as a Microsoft Teams call to slip past corporate defenses and plant EtherRAT, a stealthy cross-platform remote access trojan.

DragonForce

Cybercriminals are using fake IT support calls on Microsoft Teams to persuade employees to surrender control of their PCs before installing the EtherRAT remote access trojan... EtherRAT is a Node.js RAT that runs across Windows, Linux, and macOS...

Lazarus

Ultimately, Atos Researchers identified it to be an EtherRat malware, a recently emerging threat using Ethereum to store C2 URL addresses, preventing takedown of the infrastructure.

Contagious Interview

this payload, dubbed EtherRAT, represents something far more sophisticated. It is a persistent access implant that combines techniques from at least three documented campaigns into a single, previously unreported attack chain.

DPRK

“this payload, dubbed EtherRAT… is a persistent access implant… EtherRAT leverages Ethereum smart contracts for command-and-control (C2) resolution…”

Exploited software

Vulnerabilities linked to EtherRAT

1 CVEs

MITRE ATT&CK

EtherRAT in ATT&CK

92 distinct techniques

Techniques

92 techniques
T1021.002 SMB/Windows Admin Shares T1218 System Binary Proxy Execution T1090 Proxy T1136 Create Account T1218.007 Msiexec T1562 Impair Defenses T1003 OS Credential Dumping T1568 Dynamic Resolution T1071 Application Layer Protocol T1053.005 Scheduled Task T1547.001 Registry Run Keys / Startup Folder T1098 Account Manipulation T1570 Lateral Tool Transfer T1136.001 Local Account T1560 Archive Collected Data T1219 Remote Access Tools T1105 Ingress Tool Transfer T1053 Scheduled Task/Job T1059.007 JavaScript T1047 Windows Management Instrumentation T1059.001 PowerShell T1102.001 Dead Drop Resolver T1112 Modify Registry T1071.001 Web Protocols T1059.003 Windows Command Shell T1140 Deobfuscate/Decode Files or Information T1204 User Execution T1566.004 Spearphishing Voice T1036 Masquerading T1566 Phishing T1078 Valid Accounts T1021 Remote Services T1059 Command and Scripting Interpreter T1564.001 Hidden Files and Directories T1497.001 System Checks T1098.004 SSH Authorized Keys T1190 Exploit Public-Facing Application T1543.002 Systemd Service T1649 Steal or Forge Authentication Certificates T1005 Data from Local System T1598.004 Spearphishing Voice T1566.001 Spearphishing Attachment T1656 Impersonation T1543 Create or Modify System Process T1598 Phishing for Information T1129 Shared Modules T1204.002 Malicious File T1090.002 External Proxy T1095 Non-Application Layer Protocol T1027 Obfuscated Files or Information T1497 Virtualization/Sandbox Evasion T1564.003 Hidden Window T1033 System Owner/User Discovery T1082 System Information Discovery T1027.002 Software Packing T1566.002 Spearphishing Link T1041 Exfiltration Over C2 Channel T1203 Exploitation for Client Execution T1546.004 Unix Shell Configuration Modification T1555 Credentials from Password Stores T1083 File and Directory Discovery T1046 Network Service Discovery T1059.004 Unix Shell T1053.003 Cron T1057 Process Discovery T1526 Cloud Service Discovery T1547 Boot or Logon Autostart Execution T1037 Boot or Logon Initialization Scripts T1556 Modify Authentication Process T1613 Container and Resource Discovery T1614.001 System Language Discovery T1482 Domain Trust Discovery T1564 Hide Artifacts T1657 Financial Theft T1566.003 Spearphishing via Service T1620 Reflective Code Loading T1608.006 SEO Poisoning T1055 Process Injection T1070 Indicator Removal T1195 Supply Chain Compromise T1547.013 XDG Autostart Entries T1567 Exfiltration Over Web Service T1210 Exploitation of Remote Services T1518 Software Discovery T1548.003 Sudo and Sudo Caching T1555.003 Credentials from Web Browsers T1552.001 Credentials In Files T1037.004 RC Scripts T1552.004 Private Keys T1027.011 Fileless Storage T1016 System Network Configuration Discovery T1102 Web Service

Reporting

Research mentioning EtherRAT

Jul 27
Cyber Security News

BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware Through Fake Zoom Calls

North Korean threat actors linked to BlueNoroff are running a targeted phishing campaign that impersonates Zoom and Microsoft Teams to compromise victims in the cryptocurrency sector. Researchers said the operation abuses hijacked Telegram accounts belonging to trusted real-world contacts, sending fake Calendly and meeting links that lead targets into staged video calls. The phishing kit captures webcam images, fingerprints browsers, checks for cryptocurrency-wallet indicators, and selectively advances only high-value victims to the next stage. Investigators also observed at least five versions of the kit between late May and mid-July, indicating active development and refinement. The campaign supports both Windows and macOS and uses a ClickFix-style lure to trick victims into executing malicious commands themselves. Reported post-click activity on Windows includes a PowerShell loader, a VBScript implant launched through wscript.exe, attempts to add Microsoft Defender exclusions, checks for Telegram sessions, and enumeration of browser extensions before possible follow-on payload delivery. Researchers also found the actors using AI-generated headshots composited onto authentic body movements from prior victims to make fake meetings appear convincing, turning routine video-call invitations into a highly selective malware-delivery pipeline.

Jul 27
Cryptika

BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware Through Fake Zoom Calls | Cryptika Cybersecurity

Jul 24
Trojan Killer News

BlueNoroff Zoom/Teams Kit Turns Calls Into ClickFix Malware | Trojan Killer

Jul 24
The Hacker News

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

Jul 21
Shroudcloud

ClickFix to EtherHiding - ShroudCloud

A ClickFix-style social engineering chain tricked a Windows user into running a PowerShell one-liner from the Run dialog, launching a multi-stage malware infection that deployed two Python-based payloads. The first stage downloaded a fake Intel Software Updater Inno Setup package, unpacked a bundled CPython 3.11 runtime, and launched a Python RAT that established persistence, profiled the host, and resolved follow-on command-and-control through the Ethereum blockchain using EtherHiding. A second PowerShell stage was then delivered over STDIN, downloading another Python runtime and payload into ProgramData, where mod.pyc decrypted its next stage with an inline RC4 routine before moving toward process injection into winver.exe and a UAC elevation attempt involving AppInfo and consent.exe. The activity aligns with a broader malware-delivery ecosystem previously linked to UNC5142, which used EtherHiding-backed infrastructure and rapidly changing hosting on Cloudflare Pages (pages.dev), Backblaze B2, and domains such as bluetroniq.vip and bytevista.cloud. Observed lures frequently impersonated verification and security workflows, including fake reCAPTCHA, human verification, DNS resolver, IP provider, and macOS browser update pages, with staging paths such as /support, /win, and /start indicating payload delivery and redirection infrastructure designed to support social engineering and malware distribution at scale.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.