EtherRAT Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
11
occurrences
First Seen
December 9, 2025
Last Seen
May 2, 2026

EtherRAT is a malware family tracked across 6 threat clusters and 11 intelligence report mentions on ThreatCluster. First observed December 9, 2025; most recent activity May 2, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • EtherRAT Malware Targets Windows Through Fake Tftpd64 Installer — Mexc · May 2, 2026
  • More sophisticated EtherRAT malware variant delivered via trojanized installer — Scworld · May 1, 2026
  • EtherRAT Campaign Uses SEO Poisoning and GitHub Facades to Target Enterprise Admins — Cybersecuritynews · May 1, 2026
  • EtherRAT Uses SEO Poisoning and Fake GitHub Pages to Target Enterprise Admins — Gbhackers · May 1, 2026
  • New EtherRAT Variant Uses Trojanized Tftpd64 Installer to Bridge Web2 Malware and Web3 Theft — Cybersecuritynews · April 30, 2026
  • Ethereum-Based EtherRAT, EtherHiding Power Stealthy Malware Campaigns — Gbhackers · April 1, 2026
  • Hackers Use EtherRAT and EtherHiding to Hide Malware Infrastructure on Ethereum — Cybersecuritynews · April 1, 2026
  • RondoDox botnet exploits React2Shell flaw to breach Next.js servers — Bleepingcomputer · December 31, 2025

CVSS v3.1 Breakdown