#EtherRAT

Malware/Tool

2025-12-08 • EtherRAT: DPRK uses novel Ethereum implant in React2Shell attacks

EtherRAT is a remote-access trojan whose operators use Ethereum blockchain data to discover command-and-control infrastructure through a technique known as EtherHiding. Campaigns delivered it through ClickFix lures and malicious MSI installers disguised as common IT administration tools. The blockchain layer separates the installed payload from its current network destination, allowing operators to change infrastructure without rebuilding or redistributing the malware. The activity has tentative overlap with DPRK-associated tradecraft, while its delivery and infrastructure design emphasize flexible redirection to attacker-controlled command-and-control servers.

Tagged Reports

« Back