logo

Takedown-Proof: Inside the Ethereum-Powered “EtherRAT” and North Korea’s New Blockchain Backdoor

ID: 8b0425ff-927a-5b2f-b8b0-734da7ae259f

STIX ID: report--8b0425ff-927a-5b2f-b8b0-734da7ae259f

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-01

Date Updated: 2026-04-23

Author: Ddos

...
...

eSentire's TRU detected a sophisticated EtherRAT campaign targeting the retail sector: a Node.js backdoor linked to North Korean APT actors that uses Teams-based social engineering for initial access and stores/upates C2 via Ethereum smart contracts to make infrastructure takedown-resistant; the malware employs LOLBin execution, encrypted multi-stage payloads, registry persistence, extensive fingerprinting, and a CIS-language kill-switch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.