Skip to content
New EtherRAT Malware Variant Targets Windows Users via Trojanized Installer

New EtherRAT Malware Variant Targets Windows Users via Trojanized Installer

First seen 2 May 2026, 02:09 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 3, 2026 at 02:02 UTC
  • EtherRAT malware is delivered via a trojanized Tftpd64 installer from a spoofed GitHub repository.
  • The malware conducts system reconnaissance and targets Ethereum wallets for theft.
  • Organizations are urged to download software only from official sources to mitigate risks.

A sophisticated variant of the EtherRAT malware has been identified, delivered through a compromised version of the TFTP server tool, Tftpd64. Cybercriminals are targeting IT administrators and network professionals by embedding this malware in a trojanized installer from a spoofed GitHub repository. Once executed, the malware establishes a hidden directory and deploys a Node.js runtime to evade detection. It then conducts system reconnaissance and targets Ethereum RPC endpoints and wallet addresses for cryptocurrency theft. Organizations are advised to download software only from official sources and monitor suspicious registry entries. The attack combines traditional malware techniques with cryptocurrency theft, making it particularly dangerous. The scope of impact is significant, affecting users who may unknowingly download the malicious installer. Current status indicates ongoing risks as the malware remains undetected by many security tools.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 131d ago How this analysis works

Timeline

2026-04-30
Cybersecuritynews reports on new EtherRAT variant.
2026-05-01
Scworld publishes detailed analysis of EtherRAT malware.

More articles in this cluster (3)

Following this threat?

Track EtherRAT in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed