logo

Hackers Weaponize SEO and Fake GitHub Repos In EtherRAT Admin Assault

ID: 0d6257c8-923f-532b-b990-01dde8539273

STIX ID: report--0d6257c8-923f-532b-b990-01dde8539273

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-05-01

Date Updated: 2026-05-01

Author: Varshini

...
...

Atos uncovered an active March 2026 targeted campaign delivering a JavaScript-based RAT (EtherRAT) via SEO-poisoned search results and fake GitHub repositories that lure enterprise administrators into installing malicious MSI packages. The multi-stage payload drops an obfuscated .cmd and uses Node.js at runtime, in-memory execution, persistence via the Windows Run key, AES-256-CBC layered encryption, and a resilient blockchain-based command-and-control channel (Ethereum smart contract queried via public RPC endpoints) to receive C2 addresses and commands, enabling stealthy remote execution and data theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.