EtherRAT Malware Campaign Exploits Ethereum for Stealthy Attacks

EtherRAT Malware Campaign Exploits Ethereum for Stealthy Attacks

First seen 1 Apr 2026, 14:00 UTC CybersecuritynewsGbhackers 92% similarity 70.8

Article Content

Browse articles
ThreatCluster

Hackers are leveraging the Ethereum blockchain to deploy a sophisticated Node.js backdoor known as EtherRAT, utilizing a technique called EtherHiding to obscure their command-and-control (C2) infrastructure. This malware allows attackers to execute arbitrary commands on compromised systems, posing a significant risk to organizations across various sectors. EtherRAT has been linked to North Korean cyber operations, specifically the 'Contagious Interview' activity. The stealthy nature of EtherHiding complicates detection and mitigation efforts, making it challenging for cybersecurity professionals to respond effectively. Current reports indicate that EtherRAT is actively targeting multiple organizations, with the potential for widespread impact. The ongoing campaign highlights the evolving tactics used by cybercriminals to exploit blockchain technology for malicious purposes.

Key Points: • EtherRAT is a Node.js backdoor that enables full remote control over compromised machines. • The malware campaign is linked to North Korean cyber activity and utilizes Ethereum for stealth. • EtherHiding makes the command-and-control infrastructure difficult to detect and disrupt.

ThreatCluster AI

Timeline

2026-04-01
Gbhackers and Cybersecuritynews report on EtherRAT and EtherHiding
Date unknown
EtherRAT linked to North Korean 'Contagious Interview' activity
Date unknown
EtherRAT actively targeting organizations across multiple sectors

Community

Browse all →

Tracked Entities in This Story