logo

EtherRAT Variant Links Web2 Malware To Web3 Crypto Theft

ID: 1e05afa9-79aa-5a01-8522-6c6a07d5d7e0

STIX ID: report--1e05afa9-79aa-5a01-8522-6c6a07d5d7e0

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Varshini

...
...

The report describes the convergence of credential-stealing malware and cryptocurrency drainers, highlighting StepDrainer — a multichain drainer using polished social engineering and dynamic script injection to steal funds across 20+ blockchains — and a Windows variant of EtherRAT distributed via a trojanized Tftpd64 installer that bundles a Node.js runtime, achieves registry persistence, and performs reconnaissance to facilitate theft and evasion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.