EtherRAT is a malware family tracked across 6 threat clusters and 11 intelligence report mentions on ThreatCluster. First observed December 9, 2025; most recent activity May 2, 2026.
Hackers are leveraging the Ethereum blockchain to deploy a sophisticated Node.js backdoor known as EtherRAT, utilizing a technique called EtherHiding to obscure their command-and-control (C2) infrastructure. This…
A sophisticated variant of the EtherRAT malware has been identified, delivered through a compromised version of the TFTP server tool, Tftpd64. Cybercriminals are targeting IT administrators and network professionals by…
The EtherRAT cyber campaign has emerged as a significant threat targeting enterprise administrators, DevOps engineers, and security analysts. Attackers utilize SEO poisoning and fake GitHub pages to deliver malware…
The RondoDox botnet has been exploiting the React2Shell flaw (CVE-2025-55182) to infect vulnerable .js servers with malware and cryptominers. First documented by Fortinet in July 2025, the botnet targets multiple n-day…
North Korea-linked hackers have exploited a critical flaw in web applications using a new malware called EtherRAT. This remote access trojan employs Ethereum smart contracts for communication and utilizes multiple Linux…
CrowdStrike reports that artificial intelligence will significantly alter the cyber threat landscape by 2026, with an expected rise in prompt-injection attacks and AI-driven zero-day discoveries. Security teams will…