North Korean hackers exploit React2Shell flaw in EtherRAT malware attacks
ID: 0a43dc04-868e-5150-bd10-acb3f5a2fb8f
STIX ID: report--0a43dc04-868e-5150-bd10-acb3f5a2fb8f
Feed Name: Bleeping Computer
Sysdig researchers analyzed EtherRAT, a sophisticated Linux backdoor used in post-React2Shell attacks that installs a full Node.js runtime, decrypts and runs a JavaScript implant, implements five layers of persistence (cron, bashrc, XDG autostart, systemd user service, profile injection), self-updates, and uses Ethereum smart contracts and multiple RPC providers for resilient C2; the activity is linked by overlaps to DPRK-affiliated operations and follows active exploitation of a critical React/Next.js deserialization RCE.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
