New EtherRAT Malware Variant Targets Windows Users via Trojanized Installer

New EtherRAT Malware Variant Targets Windows Users via Trojanized Installer

First seen 2 May 2026, 02:09 UTC CybersecuritynewsScworldMexc 81% similarity 67.5

Article Content

Browse articles
ThreatCluster

A sophisticated variant of the EtherRAT malware has been identified, delivered through a compromised version of the TFTP server tool, Tftpd64. Cybercriminals are targeting IT administrators and network professionals by embedding this malware in a trojanized installer from a spoofed GitHub repository. Once executed, the malware establishes a hidden directory and deploys a Node.js runtime to evade detection. It then conducts system reconnaissance and targets Ethereum RPC endpoints and wallet addresses for cryptocurrency theft. Organizations are advised to download software only from official sources and monitor suspicious registry entries. The attack combines traditional malware techniques with cryptocurrency theft, making it particularly dangerous. The scope of impact is significant, affecting users who may unknowingly download the malicious installer. Current status indicates ongoing risks as the malware remains undetected by many security tools.

Key Points: • EtherRAT malware is delivered via a trojanized Tftpd64 installer from a spoofed GitHub repository. • The malware conducts system reconnaissance and targets Ethereum wallets for theft. • Organizations are urged to download software only from official sources to mitigate risks.

ThreatCluster AI

Timeline

2026-04-30
Cybersecuritynews reports on new EtherRAT variant.
2026-05-01
Scworld publishes detailed analysis of EtherRAT malware.

Community

Browse all →