Last seven days
- First activity
- Aug 13, 2026
- Last activity
- Aug 13, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
EtherRAT is a cross-platform remote access trojan written in Node.js that has been used in Windows-domain intrusions, social-engineering campaigns, and broader post-compromise operations.
Profile source: Mallory opens in a new tabEtherRAT
EtherRAT is a cross-platform remote access trojan written in Node.js that has been used in Windows-domain intrusions, social-engineering campaigns, and broader post-compromise operations. It provides attackers with remote control of infected systems, including command execution, file manipulation, data theft, and long-term access. The malware is notable for using Ethereum blockchain infrastructure to resolve active command-and-control information, querying a smart contract rather than relying solely on hardcoded network locations. This design gives operators a resilient mechanism for rotating infrastructure and complicates disruption and tracking.
Observed Windows deployments show EtherRAT delivered through malicious MSI installers that bootstrap a Node.js runtime when needed, decrypt the embedded JavaScript implant, and establish persistence through user autorun mechanisms. In enterprise intrusions, operators have distributed those installers laterally using administrative shares, WMI, SMB, and remotely created scheduled tasks after obtaining privileged access. EtherRAT has also appeared in campaigns that abuse Microsoft Teams, where attackers impersonate IT support staff, persuade victims to grant remote control, and then use legitimate remote administration tools before executing the malware installer. Reporting also describes phishing lures, including employee-survey themed documents, as part of the initial social-engineering chain.
The malware has been associated with activity tied to an affiliate of the Gentlemen ransomware operation, where it formed part of a larger toolkit that included credential access, Active Directory collection, lateral movement, defense impairment, and fallback remote-access channels. Separate reporting indicates EtherRAT has been used beyond a single cluster and has appeared in campaigns linked to multiple threat actors. It has been observed targeting Windows environments directly and is described as capable of running on Linux and macOS as well, reflecting its Node.js-based portability.
Operationally, EtherRAT polls its controllers using web traffic patterns intended to blend in, and it can execute attacker-supplied JavaScript returned by the server, enabling flexible post-exploitation. Its role in intrusions is consistent with a persistent remote-access implant used to maintain footholds, support hands-on-keyboard activity, and facilitate follow-on actions including data theft and ransomware deployment.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2
Threat actors are weaponizing something as ordinary as a Microsoft Teams call to slip past corporate defenses and plant EtherRAT, a stealthy cross-platform remote access trojan.
Cybercriminals are using fake IT support calls on Microsoft Teams to persuade employees to surrender control of their PCs before installing the EtherRAT remote access trojan... EtherRAT is a Node.js RAT that runs across Windows, Linux, and macOS...
Ultimately, Atos Researchers identified it to be an EtherRat malware, a recently emerging threat using Ethereum to store C2 URL addresses, preventing takedown of the infrastructure.
this payload, dubbed EtherRAT, represents something far more sophisticated. It is a persistent access implant that combines techniques from at least three documented campaigns into a single, previously unreported attack chain.
“this payload, dubbed EtherRAT… is a persistent access implant… EtherRAT leverages Ethereum smart contracts for command-and-control (C2) resolution…”
Exploited software
MITRE ATT&CK
Reporting
North Korean threat actors linked to BlueNoroff are running a targeted phishing campaign that impersonates Zoom and Microsoft Teams to compromise victims in the cryptocurrency sector. Researchers said the operation abuses hijacked Telegram accounts belonging to trusted real-world contacts, sending fake Calendly and meeting links that lead targets into staged video calls. The phishing kit captures webcam images, fingerprints browsers, checks for cryptocurrency-wallet indicators, and selectively advances only high-value victims to the next stage. Investigators also observed at least five versions of the kit between late May and mid-July, indicating active development and refinement. The campaign supports both Windows and macOS and uses a ClickFix-style lure to trick victims into executing malicious commands themselves. Reported post-click activity on Windows includes a PowerShell loader, a VBScript implant launched through wscript.exe, attempts to add Microsoft Defender exclusions, checks for Telegram sessions, and enumeration of browser extensions before possible follow-on payload delivery. Researchers also found the actors using AI-generated headshots composited onto authentic body movements from prior victims to make fake meetings appear convincing, turning routine video-call invitations into a highly selective malware-delivery pipeline.
A ClickFix-style social engineering chain tricked a Windows user into running a PowerShell one-liner from the Run dialog, launching a multi-stage malware infection that deployed two Python-based payloads. The first stage downloaded a fake Intel Software Updater Inno Setup package, unpacked a bundled CPython 3.11 runtime, and launched a Python RAT that established persistence, profiled the host, and resolved follow-on command-and-control through the Ethereum blockchain using EtherHiding. A second PowerShell stage was then delivered over STDIN, downloading another Python runtime and payload into ProgramData, where mod.pyc decrypted its next stage with an inline RC4 routine before moving toward process injection into winver.exe and a UAC elevation attempt involving AppInfo and consent.exe. The activity aligns with a broader malware-delivery ecosystem previously linked to UNC5142, which used EtherHiding-backed infrastructure and rapidly changing hosting on Cloudflare Pages (pages.dev), Backblaze B2, and domains such as bluetroniq.vip and bytevista.cloud. Observed lures frequently impersonated verification and security workflows, including fake reCAPTCHA, human verification, DNS resolver, IP provider, and macOS browser update pages, with staging paths such as /support, /win, and /start indicating payload delivery and redirection infrastructure designed to support social engineering and malware distribution at scale.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.