EtherRAT is a Node.js-based remote access trojan targeting Windows workstations and Linux servers. It provides persistent remote access and executes attacker-supplied JavaScript through a legitimate Node.js runtime, which it can download when absent. Its functionality includes modules for credential theft, lateral movement, and web-server hijacking. Windows variants establish persistence through a user-level Run key and conceal their JavaScript payloads using encryption and innocuous-looking configuration or data-file extensions.
EtherRAT uses EtherHiding, a blockchain-based dead drop resolution technique, to discover its command-and-control infrastructure. It queries Ethereum smart contracts through public JSON-RPC services, decodes the returned data, and connects to the external server specified by the contract. Operators can update the contract to redirect existing infections without replacing the malware. Observed samples periodically refresh this configuration and support multiple public RPC gateways. The blockchain acts as an infrastructure resolver rather than the server handling all commands. EtherRAT also disguises polling requests with randomized paths and common-looking extensions.
Windows delivery includes phishing, malicious copy-and-paste lures, and MSI installers masquerading as legitimate utilities or hotfixes. Hospitality-focused phishing campaigns use fabricated guest complaints, negative reviews, and legal threats to deliver archives containing malicious Windows shortcuts disguised as images. Linux infections have involved exploitation of server-side vulnerabilities. An affiliate of The Gentlemen ransomware operation has deployed EtherRAT across Windows domains through remote scheduled tasks and silently installed MSI packages, using it as part of a broader post-exploitation toolkit to maintain access before ransomware activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Q2: What is the CVE identifier for the vulnerability exploited in this attack? ... CVE-2025–55182 ... it’s a payload that abuses a JavaScript weakness (prototype pollution + constructor escape) to escape normal restrictions, then executes the system command id on the server. | CallMeOnTheChain - EtherRAT ... Q4: What is the filename of the decrypted implant that serves as the main RAT?
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Gentlemen ransomware affiliate used LOLBAS techniques, scheduled tasks, and MSI payloads to deploy EtherRAT across Windows networks.
Threat actors are weaponizing something as ordinary as a Microsoft Teams call to slip past corporate defenses and plant EtherRAT, a stealthy cross-platform remote access trojan.
Cybercriminals are using fake IT support calls on Microsoft Teams to persuade employees to surrender control of their PCs before installing the EtherRAT remote access trojan... EtherRAT is a Node.js RAT that runs across Windows, Linux, and macOS...
Ultimately, Atos Researchers identified it to be an EtherRat malware, a recently emerging threat using Ethereum to store C2 URL addresses, preventing takedown of the infrastructure.
this payload, dubbed EtherRAT, represents something far more sophisticated. It is a persistent access implant that combines techniques from at least three documented campaigns into a single, previously unreported attack chain.
“this payload, dubbed EtherRAT… is a persistent access implant… EtherRAT leverages Ethereum smart contracts for command-and-control (C2) resolution…”
29 distinct techniques documented for this family, organized by ATT&CK tactic.
The attackers used administrative shares, Windows Management Instrumentation, and remote task registration to reach internal hosts.
The operators used remote scheduled tasks to push malicious installer packages to other systems.
The recovered script below creates remote scheduled tasks that download and silently install an MSI package.
One task ran under the SYSTEM account and downloaded a PowerShell script from the staging server.
deploy2.cmd uses a batch for loop to iterate through local IP addresses, creating remote Scheduled Tasks named WinSvcUpdate2.
Attackers downloaded the official Node.js installer and used the trusted, signed node.exe runtime to execute attacker JavaScript and deploy a malicious implant.
The operators used remote scheduled tasks to push malicious installer packages to other systems.
The recovered script below creates remote scheduled tasks that download and silently install an MSI package.
The script created a local administrator account, attempted to add it to Domain Admins
The intrusion enables RDP, disables RDP Network Level Authentication, modifies UAC-related policy values and creates the EtherRAT Run value.
The operators used remote scheduled tasks to push malicious installer packages to other systems.
The recovered script below creates remote scheduled tasks that download and silently install an MSI package.
A user executed a malicious MSI installer impersonating the Sysinternals RAMMap utility.
EtherRAT queried Ethereum for its command-and-control configuration... The attacker later updated the configuration to point to a TryCloudflare tunnel, enabling communications with the installed malware.
Decrypted agent traffic to syshex6495[.]com (/agent/v2/handshake, beacon, task-ack, result)... AdaptixC2 agent... begins high volume HTTP beaconing.
The script created a local administrator account, attempted to add it to Domain Admins, disabled security services, exported registry hives, and set up a tunnel for remote access.
At the time of publication, Phexia is unique from other macOS stealers in its use of dead drop resolution with Telegram, Steam, and blockchain smart contracts to discover command and control (C2) domains for communication.
The use of a blockchain to resolve C2 infrastructure, also known as blockchain-based dead drop resolving, is a novel technique to create more persistent ways of providing updated C2s to infected hosts.
A Node.js runtime is downloaded from nodejs[.]org... ffmpeg pulled from gyan[.]dev... Chisel tunneling client... and win.exe... fetched from external infrastructure.
221 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
102 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
NodeJS-based malware delivered through malicious LNK shortcuts in archives linked from fake hospitality complaint emails. It resolves its current command-and-control address through an Ethereum smart contract, allowing operators to rotate infrastructure through blockchain transactions without redistributing the malware.
Delivered to hotel staff through fake guest complaints and negative reviews linking to archives containing a malicious Windows shortcut disguised as a JPG. The shortcut downloads Node.js and installs the malware. EtherRAT queries an Ethereum smart contract through a public JSON-RPC service, decodes the returned data, and removes masking to recover its current C2 address. This blockchain dead-drop mechanism lets operators redirect existing infections to replacement servers without distributing a new malware file.
Delivered through fake hotel guest complaints and malicious LNK shortcuts disguised as images. Runs through a downloaded NodeJS runtime and queries an Ethereum smart contract through a public JSON-RPC endpoint to retrieve an encoded C2 address. Operators can update that address through blockchain transactions without redistributing the malware, making infrastructure rotation inexpensive and conventional takedowns insufficient to disrupt persistent infections.
A remote-access implant that uses an Ethereum smart contract to retrieve an updateable C2 address, checking the contract approximately every five minutes. This enables operators to rotate C2 infrastructure without reinstalling the malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.