logo

EtherRAT Uses SEO Poisoning and Fake GitHub Pages to Target Enterprise Admins

ID: c19ba9fb-69ef-50c5-b467-779d473314f0

STIX ID: report--c19ba9fb-69ef-50c5-b467-779d473314f0

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-05-01

Date Updated: 2026-05-01

Author: Mayura Kathir

...
...

Atos Threat Research Center uncovered "EtherRAT," a sophisticated targeted campaign that poisons search results to present malicious GitHub facade repositories as trusted administrative tool downloads, redirecting victims to MSI installers that deploy a multi-stage, fileless JavaScript RAT which uses an Ethereum smart contract for dynamic C2; the operation targets high-privilege IT professionals, has at least 44 observed facade repositories, and emphasizes stealth and infrastructure resilience.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.