EtherRAT

First seen
2022-06-15 00:00:00
Malware type
rat
Family
Malware family
Last IoC activity
2026-07-22 00:37:53
Profile updated
2026-07-07 14:32:53

Targeted industries: financial-services technology-and-telecommunications

Context

According to sysdig, EtherRAT uses Ethereum smart contracts for C2 URL resolution. It establishes persistence through five independent mechanisms, ensuring survival across reboots and system maintenance (systemd, xdg, cron, bashrc, profile).

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Js.Ether Rat (report)
  • sysdig.com — Etherrat Dissected How A React2Shell Implant Delivers 5 Payloads Through Blockchain C2 (report)
  • sysdig.com — Etherrat Dprk Uses Novel Ethereum Implant In React2Shell Attacks (report)

External references