EtherRAT
- First seen
- 2022-06-15 00:00:00
- Malware type
- rat
- Family
- Malware family
- Last IoC activity
- 2026-07-22 00:37:53
- Profile updated
- 2026-07-07 14:32:53
Targeted industries: financial-services technology-and-telecommunications
Context
According to sysdig, EtherRAT uses Ethereum smart contracts for C2 URL resolution. It establishes persistence through five independent mechanisms, ensuring survival across reboots and system maintenance (systemd, xdg, cron, bashrc, profile).
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Js.Ether Rat (report)
- sysdig.com — Etherrat Dissected How A React2Shell Implant Delivers 5 Payloads Through Blockchain C2 (report)
- sysdig.com — Etherrat Dprk Uses Novel Ethereum Implant In React2Shell Attacks (report)