Malware

EtherRAT

According to sysdig, EtherRAT uses Ethereum smart contracts for C2 URL resolution. It establishes persistence through five independent mechanisms, ensuring survival across reboots and system maintenance (systemd, xdg, cron, bashrc, profile).

Indicators of Compromise 11

MITRE ATT&CK TTPs 37

T1016
System Network Configuration Discovery
Discovery
T1021.001
Remote Desktop Protocol
Lateral Movement
T1027
Obfuscated Files or Information
Defense Evasion
T1053.005
Scheduled Task
Execution
T1055
Process Injection
Defense Evasion
T1055.012
Process Hollowing
Defense Evasion
T1056.003
Web Portal Capture
Collection
T1059.001
PowerShell
Execution
T1059.007
JavaScript
Execution
T1070.004
File Deletion
Defense Evasion
T1071.001
Web Protocols
Command And Control
T1071.004
DNS
Command And Control
T1074.001
Local Data Staging
Collection
T1078
Valid Accounts
Defense Evasion
T1080
Taint Shared Content
Lateral Movement
T1082
System Information Discovery
Discovery
T1085
T1085
T1087.002
Domain Account
Discovery
T1090.004
Domain Fronting
Command And Control
T1095
Non-Application Layer Protocol
Command And Control
T1098.004
SSH Authorized Keys
Persistence
T1105
Ingress Tool Transfer
Command And Control
T1113
Screen Capture
Collection
T1133
External Remote Services
Persistence
T1202
Indirect Command Execution
Defense Evasion
T1204.002
Malicious File
Execution
T1210
Exploitation of Remote Services
Lateral Movement
T1212
Exploitation for Credential Access
Credential Access
T1484.001
Group Policy Modification
Defense Evasion
T1485
Data Destruction
Impact
T1496
Resource Hijacking
Impact
T1548
Abuse Elevation Control Mechanism
Privilege Escalation
T1555
Credentials from Password Stores
Credential Access
T1557.001
LLMNR/NBT-NS Poisoning and SMB Relay
Credential Access
T1558.003
Kerberoasting
Credential Access
T1566
Phishing
Initial Access
T1647
Plist File Modification
Defense Evasion

Source Articles

ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories
Multiple active threat campaigns were reported, including a new SideWinder attack chain using ClickOnce files to deploy Rust-based backdoors, a large-scale npm supply chain attack named 'Flooding Dropper' involving 846 malicious packages, and a Chinese threat actor leveraging a DeepSeek AI agent in an LLM-managed campaign for proxyjacking. A new XCSSET macOS malware variant (v40) spreads via compromised Xcode projects and includes a Telegram trojanizer. The Gentlemen ransomware affiliate deployed EtherRAT, which retrieves C2 data from an Ethereum smart contract. Additionally, Interlock ransomware abused Volatility3 to extract credentials from memory, and a critical RCE flaw in the Odysseus AI workspace allowed authenticated users to execute OS commands. Several phishing campaigns used fake Bank of America and Coldcard wallet lures to install ScreenConnect, while AI-powered scam farms like FunFoneFarm lower the barrier to entry for cybercrime.
hacker-news ·3w ago
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories
This week's threat landscape highlights a range of cyber activities, from cloud bucket hijacking and ransomware tooling overlaps to social engineering campaigns and supply chain attacks. Notable incidents include a global fraud operation resulting in nearly 6,000 arrests, typosquatting of payment SDKs on npm and PyPI, and the abuse of Microsoft Teams for delivering EtherRAT. Additionally, new techniques like Process Parameter Poisoning and ADFS token forgery underscore evolving evasion and privilege escalation methods.
hacker-news ·1mo ago
Fake IT support calls on Microsoft Teams push EtherRAT malware
Threat actors are conducting fake IT support calls via Microsoft Teams to trick employees into installing the EtherRAT malware. The attack begins with a phishing email containing a malicious PDF, followed by a voice call from an external Teams account impersonating system administrators. Attackers use legitimate remote access tools like HopToDesk and AnyDesk, then deploy EtherRAT via a malicious MSI installer, enabling full system control and data theft. EtherRAT uses Ethereum smart contracts for C2 resilience, and the campaign is actively evolving with multiple malware versions observed.
bleeping-computer ·1mo ago