Nknews
North Korea-linked EtherRAT Malware Exploits React2Shell Vulnerability
First seen 10 Dec 2025, 09:47 UTC
•

•58.6
Export
Article Content
Browse articles
North Korea-linked hackers have exploited a critical flaw in web applications using a new malware called EtherRAT. This remote access trojan employs Ethereum smart contracts for communication and utilizes multiple Linux persistence mechanisms, indicating a significant evolution in cybercriminal techniques. The malware was identified in a compromised JavaScript application shortly after the React2Shell vulnerability was disclosed.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Persistent Firestarter Malware Targets Cisco Firepower Devices in US Agencies
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
North Korean Hackers Utilize EtherHiding for Cryptocurrency Theft
Void Dokkaebi's Malware Campaign Exploits Developer Repositories via Fake Job Interviews
North Korean Hackers Use SVG Steganography in Job Scam Malware Campaign
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments