logo

EtherRAT dissected: How a React2Shell implant delivers 5 payloads through blockchain C2

ID: c130d41e-ea53-5738-bca8-fe6e17df0c37

STIX ID: report--c130d41e-ea53-5738-bca8-fe6e17df0c37

Feed Name: Sysdig Blog

Threat Score
85/100

Date Published: 2025-12-16

Date Updated: 2026-05-01

...
...

Sysdig Threat Research Team uncovered EtherRAT, a fileless Node.js implant deployed via the React2Shell exploit (CVE-2025-55182) that uses an Ethereum smart-contract for resilient C2. EtherRAT comprises reconnaissance (with a CIS-locale exclusion), an advanced cryptocurrency- and cloud-credential harvester (BIP39-aware), a self-spreading Next.js worm that targets private and public IP ranges, a web-server hijacker used for traffic monetization, and an SSH key backdoor; live payloads, C2 history, and comprehensive IOCs are provided, while attribution remains ambiguous between DPRK-linked patterns and CIS-associated tradecraft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.