logo

EtherRAT Distribution Spoofing Administrative Tools via GitHub Facades

ID: 5970b09e-b238-56a0-9650-b5870efad044

STIX ID: report--5970b09e-b238-56a0-9650-b5870efad044

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: [email protected] (The Hacker News)

...
...

Atos TRC describes an active, highly-resilient campaign that uses SEO-poisoned GitHub facade repositories to distribute malicious MSI installers impersonating admin tools (e.g., PsExec, AzCopy, Sysmon, LAPS). The payload, identified as EtherRAT, is a multi-stage Node.js RAT that loads in-memory, establishes persistence via registry Run keys, and resolves its C2 dynamically from an Ethereum smart contract queried through public RPC endpoints—enabling rapid C2 rotation and robust takedown resistance. The campaign specifically targets high-privilege enterprise administrators and DevOps engineers, has deployed dozens of facade repositories, includes multiple variants and IoCs, and the report provides detection and mitigation recommendations (block ETH RPCs, retrospective log review, tool provenance checks, and behavioral hunting).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.