Hackers Weaponize SEO and Fake GitHub Repos In EtherRAT Admin Assault
ID: 0d6257c8-923f-532b-b990-01dde8539273
STIX ID: report--0d6257c8-923f-532b-b990-01dde8539273
Feed Name: Cyber Press
Atos uncovered an active March 2026 targeted campaign delivering a JavaScript-based RAT (EtherRAT) via SEO-poisoned search results and fake GitHub repositories that lure enterprise administrators into installing malicious MSI packages. The multi-stage payload drops an obfuscated .cmd and uses Node.js at runtime, in-memory execution, persistence via the Windows Run key, AES-256-CBC layered encryption, and a resilient blockchain-based command-and-control channel (Ethereum smart contract queried via public RPC endpoints) to receive C2 addresses and commands, enabling stealthy remote execution and data theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
