Researchers reported a stealthy malware campaign targeting enterprise administrators, DevOps engineers, and security analysts by impersonating trusted administrative and developer utilities in malicious MSI installers. The operation used SEO poisoning to push victims toward spoofed tool listings and a dual-stage GitHub distribution chain in which benign-looking facade repositories redirected users to secondary repositories hosting the real payload, enabling operators to rotate malware quickly while preserving search credibility. At least 44 GitHub facade repositories spoofing IT tools were observed between December 2025 and early April 2026.
The payload, EtherRAT, is a multi-stage Node.js remote access trojan that downloads Node.js at runtime, establishes registry-based persistence, and executes through conhost.exe with a --headless argument to reduce visibility. Researchers said the malware uses layered AES-256-CBC encryption and retrieves its live command-and-control endpoint through public Ethereum RPC services and a hardcoded smart contract, effectively using the blockchain as a dead-drop resolver that complicates domain and IP takedowns. Reporting linked the campaign to prior EtherRAT and EtherHiding activity and said the tradecraft overlaps with malware previously associated with Lazarus Group, while also noting code similarities to Tsundere, a malware family tied in other research to MuddyWater (APT34).

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
LevelBlue SpiderLabs reported that threat actors were distributing a trojanized Windows Tftpd64 utility from a spoofed GitHub repository to infect IT administrators and network professionals with a more sophisticated EtherRAT variant. The updated malware was described as combining host compromise with cryptocurrency theft, using bundled Node.js components, persistence via Windows Run keys, system reconnaissance, and interaction with Ethereum RPC endpoints and wallet addresses.
The Hacker News summarized Atos Threat Research Center's analysis, highlighting EtherRAT's Node.js-based multi-stage design, AES-256-CBC encryption, registry persistence, and blockchain-based dead-drop C2 resolution via Ethereum smart contracts. The report brought broader public attention to the campaign's technical details and resilience mechanisms.
In early April 2026, public threat research described the stealthy spoofed-tool campaign distributing EtherRAT and assessed it as suspected to be linked to a DPRK APT. The reporting also noted prior visibility from KISA and KrCERT/CC and referenced overlaps with previously attributed malware and infrastructure.
In April 2026, DFIR Report described an intrusion that began when a user ran a malicious MSI posing as Sysinternals RAMMap, installing an EtherRAT variant that resolved C2 via Ethereum infrastructure. The actor then deployed TukTuk, conducted credential theft and lateral movement, exfiltrated data with Rclone to Wasabi, and ultimately pushed The Gentlemen ransomware domain-wide via a malicious GPO.
By April 1, 2026, Atos had identified 44 GitHub facade repositories tied to the EtherRAT distribution effort. The finding showed sustained and organized abuse of GitHub to distribute the malware at scale.
The malware operation continued through March 2026, using SEO poisoning and a dual-stage GitHub distribution model to deliver EtherRAT while allowing operators to rotate payload repositories without losing search visibility. The campaign targeted high-privilege enterprise users with spoofed administrative tools.
Atos observed the campaign using GitHub facade repositories impersonating trusted administrative and developer utilities starting in December 2025. These repositories were used to lure enterprise administrators, DevOps engineers, and security analysts into downloading malicious MSI installers.
Atos reported that the EtherRAT distribution campaign had deployed at least 17 GitHub facade repositories starting in December 2024. The finding pushes the known start of the operation back a full year earlier than previously captured and shows the campaign had been active well before its 2026 public reporting.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
thedfirreport.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcemedium.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.