Inside a malicious infrastructure delivering EtherRAT, phishing pages, and malicious software
ID: 90055224-72c8-50d4-8fd9-5f8ceda1e9db
STIX ID: report--90055224-72c8-50d4-8fd9-5f8ceda1e9db
Feed Name: Security Boulevard
Threat Score
This report details an active malicious infrastructure distributing EtherRAT — a lightweight Node.js remote access trojan that uses the Ethereum blockchain to obtain C2 endpoints — via MSI installers, PowerShell and JavaScript loaders; it describes loader behavior, custom decryption algorithms, persistence mechanisms, C2 polling formats, related phishing kits, exposed open directories, and provides IPs and domains observed in the campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
