Skip to content

EtherRAT

EtherRAT is a cross-platform remote access trojan written in Node.js that provides attackers with persistent remote control over compromised systems.

Profile source: Mallory opens in a new tab

EtherRAT

Family profile

EtherRAT is a cross-platform remote access trojan written in Node.js that provides attackers with persistent remote control over compromised systems. It has been observed on Windows, Linux, and macOS, and in some campaigns is delivered through multi-stage installers or loaders that fetch or bundle a legitimate Node.js runtime before decrypting and launching the final implant. On Linux, observed deployments have also used shell scripts and multiple persistence mechanisms including systemd user services, autostart entries, shell profile modification, crontab, and SSH key installation.

A defining characteristic of EtherRAT is its use of Ethereum-based command-and-control discovery. Rather than relying only on static infrastructure, the malware queries public Ethereum JSON-RPC endpoints and reads smart-contract state, typically via eth_call, to resolve active C2 information. This blockchain-backed resolver model increases resilience against conventional domain takedowns and has been described as an EtherHiding-style technique. Some variants also maintain fallback conventional C2 mechanisms.

Observed capabilities include arbitrary command execution, file manipulation, host reconnaissance, persistence, and data theft. Reported Linux-associated tasking has included credential and wallet theft, collection of SSH keys, cloud credentials, tokens, database secrets, and browser-stored data, as well as follow-on scripts for reconnaissance and additional exploitation activity. Windows-focused analyses have also described randomized polling patterns, self-reobfuscation behavior, and use of conhost-wrapped execution for stealth. In enterprise intrusions, EtherRAT has appeared alongside other tooling and has been propagated laterally after initial compromise.

Delivery has been associated with several intrusion patterns. Social-engineering campaigns have used phishing lures followed by Microsoft Teams voice calls in which attackers impersonated IT support, convinced victims to grant remote control, and then installed legitimate remote administration tools before deploying a malicious installer that loaded EtherRAT. Separate reporting links EtherRAT to ClickFix-style execution chains, open-directory malware distribution, trojanized software installers, and exploitation activity tied to React2Shell. The malware has been used by multiple threat clusters, including financially motivated operators, and some reporting has also linked it to campaigns assessed as state-sponsored or DPRK-related, though attribution is not uniform across all observed activity.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Reconnaissance

Reported operators

Threat actors

6 named in public reporting
DragonForce

Cybercriminals are using fake IT support calls on Microsoft Teams to persuade employees to surrender control of their PCs before installing the EtherRAT remote access trojan... EtherRAT is a Node.js RAT that runs across Windows, Linux, and macOS...

unit_42

Threat actors are now weaponizing something as ordinary as a Microsoft Teams call to slip past corporate defenses and plant a stealthy new remote access trojan called EtherRAT.

TheGentlemen

A multi-stage attack chain distributing ransomware following a Malware infection with EtherRAT and TukTuk malware was identified, and some attack methods and infrastructure were exposed through internal leaks.

Lazarus

Ultimately, Atos Researchers identified it to be an EtherRat malware, a recently emerging threat using Ethereum to store C2 URL addresses, preventing takedown of the infrastructure.

Contagious Interview

this payload, dubbed EtherRAT, represents something far more sophisticated. It is a persistent access implant that combines techniques from at least three documented campaigns into a single, previously unreported attack chain.

DPRK

“this payload, dubbed EtherRAT… is a persistent access implant… EtherRAT leverages Ethereum smart contracts for command-and-control (C2) resolution…”

Exploited software

Vulnerabilities linked to EtherRAT

1 CVEs

MITRE ATT&CK

EtherRAT in ATT&CK

83 distinct techniques

Techniques

83 techniques
T1568 Dynamic Resolution T1059 Command and Scripting Interpreter T1564.001 Hidden Files and Directories T1497.001 System Checks T1071 Application Layer Protocol T1098.004 SSH Authorized Keys T1190 Exploit Public-Facing Application T1543.002 Systemd Service T1105 Ingress Tool Transfer T1649 Steal or Forge Authentication Certificates T1036 Masquerading T1021 Remote Services T1005 Data from Local System T1566 Phishing T1078 Valid Accounts T1204 User Execution T1598.004 Spearphishing Voice T1566.001 Spearphishing Attachment T1102.001 Dead Drop Resolver T1656 Impersonation T1140 Deobfuscate/Decode Files or Information T1543 Create or Modify System Process T1219 Remote Access Tools T1598 Phishing for Information T1129 Shared Modules T1059.007 JavaScript T1562 Impair Defenses T1204.002 Malicious File T1090.002 External Proxy T1059.001 PowerShell T1095 Non-Application Layer Protocol T1112 Modify Registry T1547.001 Registry Run Keys / Startup Folder T1218.007 Msiexec T1021.002 SMB/Windows Admin Shares T1027 Obfuscated Files or Information T1497 Virtualization/Sandbox Evasion T1059.003 Windows Command Shell T1570 Lateral Tool Transfer T1071.001 Web Protocols T1564.003 Hidden Window T1053.005 Scheduled Task T1033 System Owner/User Discovery T1082 System Information Discovery T1027.002 Software Packing T1566.002 Spearphishing Link T1041 Exfiltration Over C2 Channel T1203 Exploitation for Client Execution T1546.004 Unix Shell Configuration Modification T1555 Credentials from Password Stores T1083 File and Directory Discovery T1046 Network Service Discovery T1059.004 Unix Shell T1053.003 Cron T1057 Process Discovery T1526 Cloud Service Discovery T1547 Boot or Logon Autostart Execution T1037 Boot or Logon Initialization Scripts T1556 Modify Authentication Process T1613 Container and Resource Discovery T1614.001 System Language Discovery T1482 Domain Trust Discovery T1564 Hide Artifacts T1657 Financial Theft T1566.003 Spearphishing via Service T1620 Reflective Code Loading T1608.006 SEO Poisoning T1055 Process Injection T1070 Indicator Removal T1218 System Binary Proxy Execution T1195 Supply Chain Compromise T1547.013 XDG Autostart Entries T1567 Exfiltration Over Web Service T1210 Exploitation of Remote Services T1518 Software Discovery T1548.003 Sudo and Sudo Caching T1555.003 Credentials from Web Browsers T1552.001 Credentials In Files T1037.004 RC Scripts T1552.004 Private Keys T1027.011 Fileless Storage T1016 System Network Configuration Discovery T1102 Web Service

Reporting

Research mentioning EtherRAT

Jul 27
Cyber Security News

BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware Through Fake Zoom Calls

North Korean threat actors linked to BlueNoroff are running a targeted phishing campaign that impersonates Zoom and Microsoft Teams to compromise victims in the cryptocurrency sector. Researchers said the operation abuses hijacked Telegram accounts belonging to trusted real-world contacts, sending fake Calendly and meeting links that lead targets into staged video calls. The phishing kit captures webcam images, fingerprints browsers, checks for cryptocurrency-wallet indicators, and selectively advances only high-value victims to the next stage. Investigators also observed at least five versions of the kit between late May and mid-July, indicating active development and refinement. The campaign supports both Windows and macOS and uses a ClickFix-style lure to trick victims into executing malicious commands themselves. Reported post-click activity on Windows includes a PowerShell loader, a VBScript implant launched through wscript.exe, attempts to add Microsoft Defender exclusions, checks for Telegram sessions, and enumeration of browser extensions before possible follow-on payload delivery. Researchers also found the actors using AI-generated headshots composited onto authentic body movements from prior victims to make fake meetings appear convincing, turning routine video-call invitations into a highly selective malware-delivery pipeline.

Jul 27
Cryptika

BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware Through Fake Zoom Calls | Cryptika Cybersecurity

Jul 24
Trojan Killer News

BlueNoroff Zoom/Teams Kit Turns Calls Into ClickFix Malware | Trojan Killer

Jul 24
The Hacker News

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

Jul 21
Shroudcloud

ClickFix to EtherHiding - ShroudCloud

A ClickFix-style social engineering chain tricked a Windows user into running a PowerShell one-liner from the Run dialog, launching a multi-stage malware infection that deployed two Python-based payloads. The first stage downloaded a fake Intel Software Updater Inno Setup package, unpacked a bundled CPython 3.11 runtime, and launched a Python RAT that established persistence, profiled the host, and resolved follow-on command-and-control through the Ethereum blockchain using EtherHiding. A second PowerShell stage was then delivered over STDIN, downloading another Python runtime and payload into ProgramData, where mod.pyc decrypted its next stage with an inline RC4 routine before moving toward process injection into winver.exe and a UAC elevation attempt involving AppInfo and consent.exe. The activity aligns with a broader malware-delivery ecosystem previously linked to UNC5142, which used EtherHiding-backed infrastructure and rapidly changing hosting on Cloudflare Pages (pages.dev), Backblaze B2, and domains such as bluetroniq.vip and bytevista.cloud. Observed lures frequently impersonated verification and security workflows, including fake reCAPTCHA, human verification, DNS resolver, IP provider, and macOS browser update pages, with staging paths such as /support, /win, and /start indicating payload delivery and redirection infrastructure designed to support social engineering and malware distribution at scale.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.