New EtherRAT Variant Uses Trojanized Tftpd64 Installer to Bridge Web2 Malware and Web3 Theft
ID: b7db6aa0-8873-54a1-af1a-95ad6da78799
STIX ID: report--b7db6aa0-8873-54a1-af1a-95ad6da78799
Feed Name: cybersecurityNews.com
LevelBlue/CSN analysis describes EtherRAT — a Node.js-based remote access trojan embedded in a trojanized Tftpd64 MSI hosted on a fake GitHub repo — that persists via a Windows Run registry entry, drops a bundled Node.js runtime and staged components, performs silent PowerShell reconnaissance, and includes Ethereum RPC endpoints and wallet addresses to enable crypto wallet draining; recommended mitigations include verifying downloads from official sources, monitoring Run keys invoking node.exe, and detecting non-browser outbound traffic to Ethereum RPC endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
