EtherRAT Techniques Bypass Security Via Ethereum Smart Contracts
ID: 0cac1a36-aef8-542c-8cfe-df4ecefa1875
STIX ID: report--0cac1a36-aef8-542c-8cfe-df4ecefa1875
Feed Name: Infosecurity Magazine (News)
eSentire investigators identified an EtherRAT malware campaign during a March 2026 retail incident in which attackers deployed a Node.js backdoor that retrieves C2 addresses stored in Ethereum smart contracts (a technique dubbed EtherHiding). Initial access was achieved via ClickFix attacks and IT support scams, with encrypted and obfuscated payloads establishing persistence via Windows registry keys; the malware collects extensive system and credential data, steals cryptocurrency wallets and cloud credentials, and communicates using CDN-like traffic to blend in. The report recommends disabling risky Windows utilities, training staff on IT support scams, and blocking common cryptocurrency RPC providers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
