Ethereum-Based EtherRAT, EtherHiding Power Stealthy Malware Campaigns
ID: a2393ac6-4d57-5fdd-b83f-caf1134585d0
STIX ID: report--a2393ac6-4d57-5fdd-b83f-caf1134585d0
Feed Name: GBHackers
**Executive Summary:** eSentire’s Threat Response Unit (TRU) observed EtherRAT, a Node.js backdoor that harvests credentials and crypto wallets, performs extensive host fingerprinting, and uses an Ethereum smart contract (EtherHiding) to retrieve and rotate resilient C2 endpoints; intrusions were delivered via IT support scams, ClickFix, and LOLBin abuse and employed heavy JavaScript obfuscation and reobfuscation to evade detection. TRU contained a March 2026 incident and recommends blocking unnecessary crypto RPC providers, deploying NGAV/EDR, disabling mshta.exe/pcalua.exe where possible, and enhancing phishing and IT‑support scam awareness.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
