logo

EtherRAT: DPRK uses novel Ethereum implant in React2Shell attacks

ID: a2452776-fa47-5324-ae69-6d6b1632bc5d

STIX ID: report--a2452776-fa47-5324-ae69-6d6b1632bc5d

Feed Name: Sysdig Blog

Threat Score
90/100

Date Published: 2025-12-08

Date Updated: 2026-05-01

...
...

On Dec 5, 2025 Sysdig Threat Research Team recovered and analyzed EtherRAT, a sophisticated persistent Node.js backdoor deployed via React Server Components RCE (CVE-2025-55182). EtherRAT uses a staged dropper that downloads Node.js from nodejs.org, decrypts an obfuscated payload, resolves C2 via an Ethereum smart contract with a nine-endpoint consensus mechanism, polls for and executes operator-sent JavaScript, implements five independent Linux persistence methods, and supports in-field self-updating; the report includes IOCs, hunting/detection guidance, and discussion of possible DPRK-related tool overlap.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.