Related Threat Clusters
-
EtherRAT Malware Campaign Exploits Ethereum for Stealthy Attacks
Hackers are leveraging the Ethereum blockchain to deploy a sophisticated Node.js backdoor known as EtherRAT, utilizing a technique called EtherHiding to obscure their command-and-control (C2) infrastructure. This…
2 articles · Updated April 1, 2026 -
Node.js Exploited in Ransomware Attacks Using EtherHiding Technique
Since February 2026, threat actors have been exploiting the trusted Node.js runtime to deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels. The technique…
8 articles · Updated September 3, 2026 -
New EtherRAT Malware Variant Targets Windows Users via Trojanized Installer
A sophisticated variant of the EtherRAT malware has been identified, delivered through a compromised version of the TFTP server tool, Tftpd64. Cybercriminals are targeting IT administrators and network professionals by…
3 articles · Updated May 1, 2026 -
EtherRAT Campaign Targets Enterprise Admins via SEO Poisoning and GitHub Abuse
The EtherRAT cyber campaign has emerged as a significant threat targeting enterprise administrators, DevOps engineers, and security analysts. Attackers utilize SEO poisoning and fake GitHub pages to deliver malware…
2 articles · Updated May 1, 2026 -
RondoDox Botnet Exploits React2Shell Flaw in Next.js Servers
The RondoDox botnet has been exploiting the React2Shell flaw (CVE-2025-55182) to infect vulnerable .js servers with malware and cryptominers. First documented by Fortinet in July 2025, the botnet targets multiple n-day…
1 article · Updated December 31, 2025 -
North Korea-linked EtherRAT Malware Exploits React2Shell Vulnerability
North Korea-linked hackers have exploited a critical flaw in web applications using a new malware called EtherRAT. This remote access trojan employs Ethereum smart contracts for communication and utilizes multiple Linux…
3 articles · Updated December 10, 2025 -
AI-Driven Cyber Threats Emerge as CrowdStrike Warns of 2026 Surge
CrowdStrike reports that artificial intelligence will significantly alter the cyber threat landscape by 2026, with an expected rise in prompt-injection attacks and AI-driven zero-day discoveries. Security teams will…
2 articles · Updated December 13, 2025
Recent Intelligence Reports
- Attackers Turn Trusted Node Js Runtime Into Malware Delivery Tool In Targeted Attacks — cybernoz.com · September 3, 2026
- Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks — Thehackernews · September 3, 2026
- EtherRAT Malware Targets Windows Through Fake Tftpd64 Installer — Mexc · May 2, 2026
- More sophisticated EtherRAT malware variant delivered via trojanized installer — Scworld · May 1, 2026
- EtherRAT Campaign Uses SEO Poisoning and GitHub Facades to Target Enterprise Admins — Cybersecuritynews · May 1, 2026
- EtherRAT Uses SEO Poisoning and Fake GitHub Pages to Target Enterprise Admins — Gbhackers · May 1, 2026
- New EtherRAT Variant Uses Trojanized Tftpd64 Installer to Bridge Web2 Malware and Web3 Theft — Cybersecuritynews · April 30, 2026
- Ethereum-Based EtherRAT, EtherHiding Power Stealthy Malware Campaigns — Gbhackers · April 1, 2026