EtherRAT is a Node.js-based remote access trojan that has been observed targeting Windows workstations through social-engineering delivery and Linux servers through exploitation of server-side vulnerabilities, including React2Shell. It uses blockchain-enabled dead drop resolution for command-and-control discovery, polling public Ethereum infrastructure and retrieving operational data from smart contracts, a technique associated with EtherHiding-style infrastructure abuse. EtherRAT has been described as a multi-stage intrusion set with modular functionality supporting credential theft, lateral movement, and web server hijacking. On Windows, it has been delivered through malicious copy-and-paste lures that lead to silent installation and then disguises itself as benign configuration or data artifacts to reduce suspicion. Reporting also indicates use of remote monitoring and management tooling as a precursor to ransomware operations. The tradecraft attributed to EtherRAT emphasizes stealthy delivery, resilient command-and-control discovery, and post-compromise expansion across both workstation and server environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Node.js RAT targeting Windows and Linux, using blockchain-based dead-drop C2 resolution and modules for credential theft, lateral movement, and web server hijacking.
EtherRAT is a sophisticated multi-stage attack campaign exploiting the React2Shell vulnerability, using Ethereum blockchain smart contracts for command and control, and exhibiting nation-state level TTPs.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.