logo

Inside a malicious infrastructure delivering EtherRAT, phishing pages, and malicious software 

ID: 90055224-72c8-50d4-8fd9-5f8ceda1e9db

STIX ID: report--90055224-72c8-50d4-8fd9-5f8ceda1e9db

Feed Name: Security Boulevard

Threat Score
75/100

Date Published: 2026-06-15

Date Updated: 2026-06-16

Author: Malwarebytes

...
...

This report details an active malicious infrastructure distributing EtherRAT — a lightweight Node.js remote access trojan that uses the Ethereum blockchain to obtain C2 endpoints — via MSI installers, PowerShell and JavaScript loaders; it describes loader behavior, custom decryption algorithms, persistence mechanisms, C2 polling formats, related phishing kits, exposed open directories, and provides IPs and domains observed in the campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.