logo

North Korean hackers exploit React2Shell flaw in EtherRAT malware attacks

ID: 0a43dc04-868e-5150-bd10-acb3f5a2fb8f

STIX ID: report--0a43dc04-868e-5150-bd10-acb3f5a2fb8f

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-12-09

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Sysdig researchers analyzed EtherRAT, a sophisticated Linux backdoor used in post-React2Shell attacks that installs a full Node.js runtime, decrypts and runs a JavaScript implant, implements five layers of persistence (cron, bashrc, XDG autostart, systemd user service, profile injection), self-updates, and uses Ethereum smart contracts and multiple RPC providers for resilient C2; the activity is linked by overlaps to DPRK-affiliated operations and follows active exploitation of a critical React/Next.js deserialization RCE.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.