Malware
EtherRAT
- First Reported
- May 11, 2026
- Latest Reported
- Sep 3, 2026
Reported Context (3)
- EtherRAT: Stealthy Remote Access Trojan (RAT) that is written in Node.js and is largely known for its use of "EtherHiding," a technique that conceals and updates its Command-and-Control (C&C) server addresses by hiding Attackers Revive Node.js Abuse to Run Malware and Maintain Persistence
- movement ran through remote scheduled tasks that downloaded and executed MSI payloads. Those installed EtherRAT, a persistent implant that pulls its C2 domains from an Ethereum smart contract instead of hardcoding The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum-Based C2
- The EtherRAT malware family was first reported by Sysdig back in December 2025. EtherRAT and TukTuk C2 Lead to The Gentlemen Ransomware Deployment
CVE (2)
Malware (15)
People (3)
Threat Actors (2)
MITRE ATT&CK (33)
Vendors (7)
Products (11)
Tools (15)
Industries (8)
Countries (5)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.