Cybercriminals are using fake IT support calls on Microsoft Teams to persuade employees to surrender control of their PCs before installing the EtherRAT remote access trojan... EtherRAT is a Node.js RAT that runs across Windows, Linux, and macOS...
EtherRAT
EtherRAT is a cross-platform remote access trojan written in Node.js that provides attackers with full remote control of compromised systems.
Profile source: Mallory opens in a new tabEtherRAT
Family profile
EtherRAT is a cross-platform remote access trojan written in Node.js that provides attackers with full remote control of compromised systems. It has been observed on Windows, Linux, and macOS, and has also appeared in Linux server intrusions following exploitation of CVE-2025-55182 (React2Shell). A notable architectural feature is its use of Ethereum smart contracts and public JSON-RPC infrastructure to resolve active command-and-control endpoints, increasing resilience against conventional domain-based disruption. Some variants also maintain fallback conventional C2 mechanisms.
Observed delivery chains are multi-stage and vary by campaign. On Linux, EtherRAT has been deployed after React2Shell exploitation through shell scripts that install a Node.js runtime, decrypt staged JavaScript components, and establish persistence through mechanisms such as systemd services, XDG autostart entries, crontab, and shell profile modifications. On Windows, it has been delivered through malicious MSI installers, including trojanized software installers and loaders that fetch or bundle a legitimate Node.js runtime, decrypt embedded payloads, and launch the final implant, often via conhost for stealth. It has also been distributed through open directories hosting MSI, PowerShell, and JavaScript installers. In enterprise social-engineering campaigns, attackers have used phishing emails followed by Microsoft Teams voice calls impersonating IT support, persuading victims to grant remote control and install legitimate remote administration tools before executing a malicious MSI that loads EtherRAT. EtherRAT has also appeared in ClickFix-driven intrusions as a later-stage payload after initial compromise by other loaders.
Capabilities consistently attributed to EtherRAT include remote command execution, arbitrary JavaScript execution delivered by the C2, file manipulation, data theft, reconnaissance, and persistence. Linux-associated activity linked to EtherRAT has included delivery of follow-on scripts for host profiling, credential and wallet theft, SSH key installation, React2Shell scanning and exploitation, and web-server configuration abuse. Windows variants have been observed performing host reconnaissance such as locale, antivirus, GPU, domain, and session checks, and establishing persistence through Run-key execution of Node.js-based payloads. Some samples re-obfuscate themselves by sending their own source to the C2 and writing back a newly obfuscated version, complicating static detection and hash-based tracking.
EtherRAT has been associated with multiple intrusion sets and operational contexts rather than a single exclusive actor. Reporting has linked early activity to campaigns exploiting React2Shell, including activity assessed in some cases as DPRK-related or state-sponsored, while later use indicates broader adoption by criminal operators. It has been observed in hands-on-keyboard intrusions involving lateral movement, deployment across multiple hosts, coexistence with other malware families such as TukTuk and RMMProject, and use in attack chains that progressed to data theft, extortion, or ransomware deployment. Targeting has included corporate environments, public-facing Linux servers, and organizations reached through social-engineering lures abusing collaboration platforms such as Microsoft Teams.
Capabilities
- Credential Theft
- Defense Evasion
- Exfiltration
- Initial Access
- Lateral Movement
- Persistence
- Post Exploitation
- Reconnaissance
Reported operators
Threat actors
6 named in public reportingThreat actors are now weaponizing something as ordinary as a Microsoft Teams call to slip past corporate defenses and plant a stealthy new remote access trojan called EtherRAT.
A multi-stage attack chain distributing ransomware following a Malware infection with EtherRAT and TukTuk malware was identified, and some attack methods and infrastructure were exposed through internal leaks.
Ultimately, Atos Researchers identified it to be an EtherRat malware, a recently emerging threat using Ethereum to store C2 URL addresses, preventing takedown of the infrastructure.
this payload, dubbed EtherRAT, represents something far more sophisticated. It is a persistent access implant that combines techniques from at least three documented campaigns into a single, previously unreported attack chain.
“this payload, dubbed EtherRAT… is a persistent access implant… EtherRAT leverages Ethereum smart contracts for command-and-control (C2) resolution…”
Exploited software
Vulnerabilities linked to EtherRAT
1 CVEsMITRE ATT&CK
EtherRAT in ATT&CK
83 distinct techniquesTechniques
83 techniquesReporting
Research mentioning EtherRAT
Medium
CallMeOnTheChain - EtherRAT ... Q4: What is the filename of the decrypted implant that serves as the main RAT?
New Helix vishing group emerges in SharePoint data theft attacks
Related Articles: ... Fake IT support calls on Microsoft Teams push EtherRAT malware ...
Attackers use Microsoft Teams voice calls to deliver EtherRAT malware | brief | SC Media
The attacker convinces the victim to grant remote control using Teams' screen-sharing feature and guides them to install legitimate remote access tools like HopToDesk or AnyDesk. Once remote access is established, the attackers download and execute a malicious MSI installer that loads EtherRAT, a cross-platform remote access trojan.
Hackers Leverage Microsoft Teams Call to Install RMM Tools and Deploy EtherRAT - Cyber Security News
Threat actors are now weaponizing something as ordinary as a Microsoft Teams call to slip past corporate defenses and plant a stealthy new remote access trojan called EtherRAT.
Fake IT bods on Microsoft Teams coax workers into installing malware
Cybercriminals are using fake IT support calls on Microsoft Teams to persuade employees to surrender control of their PCs before installing the EtherRAT remote access trojan... EtherRAT is a Node.js RAT that runs across Windows, Linux, and macOS...
Fake IT support calls on Microsoft Teams push EtherRAT malware
Threat actors are abusing Microsoft Teams voice calls by impersonating corporate IT support staff to trick employees into installing the EtherRAT malware... The MSI acts as a malware loader, downloading a legitimate Node.js runtime, decrypting embedded payloads, and ultimately launching EtherRAT. EtherRAT is a cross-platform remote access trojan written in Node.js that gives attackers full control over compromised systems.
Phishing poses as big-brand job interview to steal Google accounts
Related Articles: Fake IT support calls on Microsoft Teams push EtherRAT malware
Someone's Hands are on Your Keyboard Then Your Whole Network. Courtesy of ClickFix, Potemkin, RMMProject and EtherRAT | Community Portal | Gurucul
The threat actors deployed EtherRAT and ultimately disabled Windows Defender completely.