logo

EtherRAT: DPRK uses novel Ethereum implant in React2Shell attacks

ID: ed84c40b-448e-53ab-9566-34437a10256d

STIX ID: report--ed84c40b-448e-53ab-9566-34437a10256d

Feed Name: Sysdig Blog

Threat Score
90/100

Date Published: 2025-12-08

Date Updated: 2026-05-01

...
...

EtherRAT is a sophisticated, persistent Node.js implant delivered via the React2Shell RCE (CVE-2025-55182) that downloads a Node.js runtime, decrypts and runs an obfuscated payload, resolves C2 using an Ethereum smart contract queried across multiple RPC endpoints (consensus-based), establishes five independent Linux persistence mechanisms, and supports remote execution and one-time self-updates; the report includes IOCs, detection and mitigation guidance, and notes partial overlap with DPRK-linked tooling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.