Gbhackers EtherRAT Malware Campaign Exploits Ethereum for Stealthy Attacks
Article Content
- •EtherRAT is a Node.js backdoor that enables full remote control over compromised machines.
- •The malware campaign is linked to North Korean cyber activity and utilizes Ethereum for stealth.
- •EtherHiding makes the command-and-control infrastructure difficult to detect and disrupt.
Hackers are leveraging the Ethereum blockchain to deploy a sophisticated Node.js backdoor known as EtherRAT, utilizing a technique called EtherHiding to obscure their command-and-control (C2) infrastructure. This malware allows attackers to execute arbitrary commands on compromised systems, posing a significant risk to organizations across various sectors. EtherRAT has been linked to North Korean cyber operations, specifically the 'Contagious Interview' activity. The stealthy nature of EtherHiding complicates detection and mitigation efforts, making it challenging for cybersecurity professionals to respond effectively. Current reports indicate that EtherRAT is actively targeting multiple organizations, with the potential for widespread impact. The ongoing campaign highlights the evolving tactics used by cybercriminals to exploit blockchain technology for malicious purposes.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track EtherHiding and Ethereum in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Node.js Exploited in Ransomware Attacks Using EtherHiding Technique Since February 2026, threat actors have been exploiting the trusted Node.js runtime to deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels. The technique leverages node.exe, a legitimate and signed developer tool, allowing attackers to run interpreted scripts…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…