logo

New EtherRAT Variant Uses Trojanized Tftpd64 Installer to Bridge Web2 Malware and Web3 Theft

ID: b7db6aa0-8873-54a1-af1a-95ad6da78799

STIX ID: report--b7db6aa0-8873-54a1-af1a-95ad6da78799

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Tushar Subhra Dutta

...
...

LevelBlue/CSN analysis describes EtherRAT — a Node.js-based remote access trojan embedded in a trojanized Tftpd64 MSI hosted on a fake GitHub repo — that persists via a Windows Run registry entry, drops a bundled Node.js runtime and staged components, performs silent PowerShell reconnaissance, and includes Ethereum RPC endpoints and wallet addresses to enable crypto wallet draining; recommended mitigations include verifying downloads from official sources, monitoring Run keys invoking node.exe, and detecting non-browser outbound traffic to Ethereum RPC endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.