logo

EtherRAT Campaign Uses SEO Poisoning and GitHub Facades to Target Enterprise Admins

ID: acb3931b-9bf4-59c3-8eb6-37fa9031682b

STIX ID: report--acb3931b-9bf4-59c3-8eb6-37fa9031682b

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-05-01

Date Updated: 2026-05-01

Author: Tushar Subhra Dutta

...
...

A sophisticated campaign is actively targeting high‑privilege IT staff by poisoning search results to surface professional-looking GitHub facades that link to hidden repositories hosting malicious MSI installers. The multi-stage payload (EtherRAT) uses an obfuscated MSI-launched batch, an in-memory Node.js stage, and a JavaScript RAT persisted to run under conhost.exe; it retrieves C2 via the Ethereum blockchain to resist takedowns. The report documents 17 separate GitHub facades (Dec 2024–Apr 2026), behavioral IOCs (high-frequency beacons, periodic ETH RPC requests, conhost.exe with headless argument), and recommended mitigations including network blocks, telemetry reviews, and stricter sourcing controls for admin tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.