logo

Ethereum-Based EtherRAT, EtherHiding Power Stealthy Malware Campaigns

ID: a2393ac6-4d57-5fdd-b83f-caf1134585d0

STIX ID: report--a2393ac6-4d57-5fdd-b83f-caf1134585d0

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-04-01

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**Executive Summary:** eSentire’s Threat Response Unit (TRU) observed EtherRAT, a Node.js backdoor that harvests credentials and crypto wallets, performs extensive host fingerprinting, and uses an Ethereum smart contract (EtherHiding) to retrieve and rotate resilient C2 endpoints; intrusions were delivered via IT support scams, ClickFix, and LOLBin abuse and employed heavy JavaScript obfuscation and reobfuscation to evade detection. TRU contained a March 2026 incident and recommends blocking unnecessary crypto RPC providers, deploying NGAV/EDR, disabling mshta.exe/pcalua.exe where possible, and enhancing phishing and IT‑support scam awareness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.