Hackers Use EtherRAT and EtherHiding to Hide Malware Infrastructure on Ethereum
ID: a9bba5dc-e85c-5260-92d2-25847a9ce539
STIX ID: report--a9bba5dc-e85c-5260-92d2-25847a9ce539
Feed Name: cybersecurityNews.com
The report details EtherRAT, a sophisticated Node.js backdoor that retrieves its C2 address from an Ethereum smart contract (EtherHiding) to maintain persistent, updateable command infrastructure; it enables remote control, cryptocurrency wallet theft, and cloud credential theft. Researchers link the tool to a North Korean APT through overlaps with the “Contagious Interview” campaign; initial access is achieved via social-engineering techniques (ClickFix via pcalua/mshta and impersonation over Microsoft Teams using QuickAssist). Targets span retail, finance, software, and business services, and the malware includes evasion, CDN-like beacons, randomized HKCU Run persistence, and self-scrambling updates to hinder detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
