logo

Hackers Use EtherRAT and EtherHiding to Hide Malware Infrastructure on Ethereum

ID: a9bba5dc-e85c-5260-92d2-25847a9ce539

STIX ID: report--a9bba5dc-e85c-5260-92d2-25847a9ce539

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-04-01

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

The report details EtherRAT, a sophisticated Node.js backdoor that retrieves its C2 address from an Ethereum smart contract (EtherHiding) to maintain persistent, updateable command infrastructure; it enables remote control, cryptocurrency wallet theft, and cloud credential theft. Researchers link the tool to a North Korean APT through overlaps with the “Contagious Interview” campaign; initial access is achieved via social-engineering techniques (ClickFix via pcalua/mshta and impersonation over Microsoft Teams using QuickAssist). Targets span retail, finance, software, and business services, and the malware includes evasion, CDN-like beacons, randomized HKCU Run persistence, and self-scrambling updates to hinder detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.