Skip to content
Malware family LinuxmacOSWindows

EtherRAT

EtherRAT is a cross-platform remote access trojan written in Node.js that provides attackers with full remote control of compromised systems.

Profile source: Mallory opens in a new tab

EtherRAT

Family profile

EtherRAT is a cross-platform remote access trojan written in Node.js that provides attackers with full remote control of compromised systems. It has been observed on Windows, Linux, and macOS, and has also appeared in Linux server intrusions following exploitation of CVE-2025-55182 (React2Shell). A notable architectural feature is its use of Ethereum smart contracts and public JSON-RPC infrastructure to resolve active command-and-control endpoints, increasing resilience against conventional domain-based disruption. Some variants also maintain fallback conventional C2 mechanisms.

Observed delivery chains are multi-stage and vary by campaign. On Linux, EtherRAT has been deployed after React2Shell exploitation through shell scripts that install a Node.js runtime, decrypt staged JavaScript components, and establish persistence through mechanisms such as systemd services, XDG autostart entries, crontab, and shell profile modifications. On Windows, it has been delivered through malicious MSI installers, including trojanized software installers and loaders that fetch or bundle a legitimate Node.js runtime, decrypt embedded payloads, and launch the final implant, often via conhost for stealth. It has also been distributed through open directories hosting MSI, PowerShell, and JavaScript installers. In enterprise social-engineering campaigns, attackers have used phishing emails followed by Microsoft Teams voice calls impersonating IT support, persuading victims to grant remote control and install legitimate remote administration tools before executing a malicious MSI that loads EtherRAT. EtherRAT has also appeared in ClickFix-driven intrusions as a later-stage payload after initial compromise by other loaders.

Capabilities consistently attributed to EtherRAT include remote command execution, arbitrary JavaScript execution delivered by the C2, file manipulation, data theft, reconnaissance, and persistence. Linux-associated activity linked to EtherRAT has included delivery of follow-on scripts for host profiling, credential and wallet theft, SSH key installation, React2Shell scanning and exploitation, and web-server configuration abuse. Windows variants have been observed performing host reconnaissance such as locale, antivirus, GPU, domain, and session checks, and establishing persistence through Run-key execution of Node.js-based payloads. Some samples re-obfuscate themselves by sending their own source to the C2 and writing back a newly obfuscated version, complicating static detection and hash-based tracking.

EtherRAT has been associated with multiple intrusion sets and operational contexts rather than a single exclusive actor. Reporting has linked early activity to campaigns exploiting React2Shell, including activity assessed in some cases as DPRK-related or state-sponsored, while later use indicates broader adoption by criminal operators. It has been observed in hands-on-keyboard intrusions involving lateral movement, deployment across multiple hosts, coexistence with other malware families such as TukTuk and RMMProject, and use in attack chains that progressed to data theft, extortion, or ransomware deployment. Targeting has included corporate environments, public-facing Linux servers, and organizations reached through social-engineering lures abusing collaboration platforms such as Microsoft Teams.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Reconnaissance

Reported operators

Threat actors

6 named in public reporting
DragonForce

Cybercriminals are using fake IT support calls on Microsoft Teams to persuade employees to surrender control of their PCs before installing the EtherRAT remote access trojan... EtherRAT is a Node.js RAT that runs across Windows, Linux, and macOS...

unit_42

Threat actors are now weaponizing something as ordinary as a Microsoft Teams call to slip past corporate defenses and plant a stealthy new remote access trojan called EtherRAT.

TheGentlemen

A multi-stage attack chain distributing ransomware following a Malware infection with EtherRAT and TukTuk malware was identified, and some attack methods and infrastructure were exposed through internal leaks.

Lazarus

Ultimately, Atos Researchers identified it to be an EtherRat malware, a recently emerging threat using Ethereum to store C2 URL addresses, preventing takedown of the infrastructure.

Contagious Interview

this payload, dubbed EtherRAT, represents something far more sophisticated. It is a persistent access implant that combines techniques from at least three documented campaigns into a single, previously unreported attack chain.

DPRK

“this payload, dubbed EtherRAT… is a persistent access implant… EtherRAT leverages Ethereum smart contracts for command-and-control (C2) resolution…”

Exploited software

Vulnerabilities linked to EtherRAT

1 CVEs

MITRE ATT&CK

EtherRAT in ATT&CK

83 distinct techniques

Techniques

83 techniques
T1568 Dynamic Resolution T1059 Command and Scripting Interpreter T1564.001 Hidden Files and Directories T1497.001 System Checks T1071 Application Layer Protocol T1098.004 SSH Authorized Keys T1190 Exploit Public-Facing Application T1543.002 Systemd Service T1105 Ingress Tool Transfer T1649 Steal or Forge Authentication Certificates T1036 Masquerading T1021 Remote Services T1005 Data from Local System T1566 Phishing T1078 Valid Accounts T1204 User Execution T1598.004 Spearphishing Voice T1566.001 Spearphishing Attachment T1102.001 Dead Drop Resolver T1656 Impersonation T1140 Deobfuscate/Decode Files or Information T1543 Create or Modify System Process T1219 Remote Access Tools T1598 Phishing for Information T1129 Shared Modules T1059.007 JavaScript T1562 Impair Defenses T1204.002 Malicious File T1090.002 External Proxy T1059.001 PowerShell T1095 Non-Application Layer Protocol T1112 Modify Registry T1547.001 Registry Run Keys / Startup Folder T1218.007 Msiexec T1021.002 SMB/Windows Admin Shares T1027 Obfuscated Files or Information T1497 Virtualization/Sandbox Evasion T1059.003 Windows Command Shell T1570 Lateral Tool Transfer T1071.001 Web Protocols T1564.003 Hidden Window T1053.005 Scheduled Task T1033 System Owner/User Discovery T1082 System Information Discovery T1027.002 Software Packing T1566.002 Spearphishing Link T1041 Exfiltration Over C2 Channel T1203 Exploitation for Client Execution T1546.004 Unix Shell Configuration Modification T1555 Credentials from Password Stores T1083 File and Directory Discovery T1046 Network Service Discovery T1059.004 Unix Shell T1053.003 Cron T1057 Process Discovery T1526 Cloud Service Discovery T1547 Boot or Logon Autostart Execution T1037 Boot or Logon Initialization Scripts T1556 Modify Authentication Process T1613 Container and Resource Discovery T1614.001 System Language Discovery T1482 Domain Trust Discovery T1564 Hide Artifacts T1657 Financial Theft T1566.003 Spearphishing via Service T1620 Reflective Code Loading T1608.006 SEO Poisoning T1055 Process Injection T1070 Indicator Removal T1218 System Binary Proxy Execution T1195 Supply Chain Compromise T1547.013 XDG Autostart Entries T1567 Exfiltration Over Web Service T1210 Exploitation of Remote Services T1518 Software Discovery T1548.003 Sudo and Sudo Caching T1555.003 Credentials from Web Browsers T1552.001 Credentials In Files T1037.004 RC Scripts T1552.004 Private Keys T1027.011 Fileless Storage T1016 System Network Configuration Discovery T1102 Web Service

Reporting

Research mentioning EtherRAT

Jul 18
Infosec Writeups

Medium

CallMeOnTheChain - EtherRAT ... Q4: What is the filename of the decrypted implant that serves as the main RAT?

Jul 9
Bleeping Computer

New Helix vishing group emerges in SharePoint data theft attacks

Related Articles: ... Fake IT support calls on Microsoft Teams push EtherRAT malware ...

Jul 7
Scworld

Attackers use Microsoft Teams voice calls to deliver EtherRAT malware | brief | SC Media

The attacker convinces the victim to grant remote control using Teams' screen-sharing feature and guides them to install legitimate remote access tools like HopToDesk or AnyDesk. Once remote access is established, the attackers download and execute a malicious MSI installer that loads EtherRAT, a cross-platform remote access trojan.

Jul 7
Cyber Security News

Hackers Leverage Microsoft Teams Call to Install RMM Tools and Deploy EtherRAT - Cyber Security News

Threat actors are now weaponizing something as ordinary as a Microsoft Teams call to slip past corporate defenses and plant a stealthy new remote access trojan called EtherRAT.

Jul 7
Register Security

Fake IT bods on Microsoft Teams coax workers into installing malware

Cybercriminals are using fake IT support calls on Microsoft Teams to persuade employees to surrender control of their PCs before installing the EtherRAT remote access trojan... EtherRAT is a Node.js RAT that runs across Windows, Linux, and macOS...

Jul 6
Bleeping Computer

Fake IT support calls on Microsoft Teams push EtherRAT malware

Threat actors are abusing Microsoft Teams voice calls by impersonating corporate IT support staff to trick employees into installing the EtherRAT malware... The MSI acts as a malware loader, downloading a legitimate Node.js runtime, decrypting embedded payloads, and ultimately launching EtherRAT. EtherRAT is a cross-platform remote access trojan written in Node.js that gives attackers full control over compromised systems.

Jul 6
Bleeping Computer

Phishing poses as big-brand job interview to steal Google accounts

Related Articles: Fake IT support calls on Microsoft Teams push EtherRAT malware

Jun 23
Gurucul Threat Research

Someone's Hands are on Your Keyboard Then Your Whole Network. Courtesy of ClickFix, Potemkin, RMMProject and EtherRAT | Community Portal | Gurucul

The threat actors deployed EtherRAT and ultimately disabled Windows Defender completely.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.