Scworld New EtherRAT Malware Variant Targets Windows Users via Trojanized Installer
Article Content
- •EtherRAT malware is delivered via a trojanized Tftpd64 installer from a spoofed GitHub repository.
- •The malware conducts system reconnaissance and targets Ethereum wallets for theft.
- •Organizations are urged to download software only from official sources to mitigate risks.
A sophisticated variant of the EtherRAT malware has been identified, delivered through a compromised version of the TFTP server tool, Tftpd64. Cybercriminals are targeting IT administrators and network professionals by embedding this malware in a trojanized installer from a spoofed GitHub repository. Once executed, the malware establishes a hidden directory and deploys a Node.js runtime to evade detection. It then conducts system reconnaissance and targets Ethereum RPC endpoints and wallet addresses for cryptocurrency theft. Organizations are advised to download software only from official sources and monitor suspicious registry entries. The attack combines traditional malware techniques with cryptocurrency theft, making it particularly dangerous. The scope of impact is significant, affecting users who may unknowingly download the malicious installer. Current status indicates ongoing risks as the malware remains undetected by many security tools.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track EtherRAT in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Node.js Exploited in Ransomware Attacks Using EtherHiding Technique Since February 2026, threat actors have been exploiting the trusted Node.js runtime to deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels. The technique leverages node.exe, a legitimate and signed developer tool, allowing attackers to run interpreted scripts…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…