EtherRAT is a cross-platform remote access trojan and backdoor written in Node.js that has been observed on Windows, Linux, and macOS, with multiple campaigns also showing strong Windows-focused tradecraft. It provides attackers with full remote control of compromised systems, including arbitrary command execution, file manipulation, data theft, and persistent access. Several analyses also show it can execute arbitrary JavaScript delivered by its command-and-control infrastructure, enabling rapid functional changes after deployment.
A defining characteristic of EtherRAT is its use of Ethereum-based infrastructure for command-and-control discovery. Rather than relying only on static domains, it queries public Ethereum RPC services and reads smart-contract state to resolve active backend infrastructure, an approach often described as EtherHiding. This design increases resilience against conventional takedown efforts and has been accompanied in some cases by fallback conventional network infrastructure.
EtherRAT has been delivered through multiple intrusion paths. Early reporting tied it to exploitation of CVE-2025-55182 (React2Shell) against Linux servers. Later campaigns used social engineering, including phishing emails and Microsoft Teams voice calls in which attackers impersonated IT or helpdesk staff, persuaded victims to grant remote control, and then executed a malicious MSI loader. Other observed delivery methods include ClickFix-style lures, trojanized software installers such as fake administrative utilities, and open-directory distribution of staged installers and scripts. Install chains commonly deploy or reuse a legitimate Node.js runtime, decrypt embedded payloads, and establish persistence before launching the final RAT.
Observed persistence mechanisms include Windows autorun entries and, on Linux, systemd services, XDG autostart entries, shell profile modification, and cron-based execution. Post-compromise behavior includes host reconnaissance, domain-awareness checks, and in some campaigns broader follow-on activity such as credential and wallet theft, SSH-key installation, React2Shell scanning and exploitation, and web-server manipulation. EtherRAT has also appeared alongside other tooling in larger intrusions involving lateral movement, remote management abuse, defense evasion, and ransomware deployment.
The malware has been associated with several distinct threat contexts rather than a single exclusive operator. It has been linked to React2Shell exploitation campaigns, Microsoft Teams helpdesk-impersonation intrusions, ClickFix-enabled compromises, and hybrid campaigns blending enterprise compromise with cryptocurrency theft. Reporting indicates active development across multiple versions and broader adoption by criminal operators beyond any original cluster.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The RAT has previously been linked to attacks exploiting the React2Shell vulnerability and has since appeared in campaigns involving multiple threat groups. | Cybercriminals are using fake IT support calls on Microsoft Teams to persuade employees to surrender control of their PCs before installing the EtherRAT remote access trojan... EtherRAT is a Node.js RAT that runs across Windows, Linux, and macOS...
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cybercriminals are using fake IT support calls on Microsoft Teams to persuade employees to surrender control of their PCs before installing the EtherRAT remote access trojan... EtherRAT is a Node.js RAT that runs across Windows, Linux, and macOS...
Threat actors are now weaponizing something as ordinary as a Microsoft Teams call to slip past corporate defenses and plant a stealthy new remote access trojan called EtherRAT.
A multi-stage attack chain distributing ransomware following a Malware infection with EtherRAT and TukTuk malware was identified, and some attack methods and infrastructure were exposed through internal leaks.
Ultimately, Atos Researchers identified it to be an EtherRat malware, a recently emerging threat using Ethereum to store C2 URL addresses, preventing takedown of the infrastructure.
this payload, dubbed EtherRAT, represents something far more sophisticated. It is a persistent access implant that combines techniques from at least three documented campaigns into a single, previously unreported attack chain.
“this payload, dubbed EtherRAT… is a persistent access implant… EtherRAT leverages Ethereum smart contracts for command-and-control (C2) resolution…”
26 distinct techniques documented for this family, organized by ATT&CK tactic.
EtherRAT can execute commands, steal data, and maintain persistence
File Path C:\Windows\Temp\D0OK1nWwId9W.ps1 First malicious PowerShell script dropped ... File Path C:\ProgramData\p\fsjH6IHuUkhh.ps1 AMSI bypass + Defender registry disable + reflective Chisel load
the attacker downloads and runs a malicious MSI installer that quietly fetches a legitimate Node.js runtime onto the compromised machine. The installer then decrypts hidden payloads bundled inside it, eventually launching the EtherRAT malware itself.
The attacker convinces the victim to grant remote control using Teams' screen-sharing feature and guides them to install legitimate remote access tools like HopToDesk or AnyDesk.
The attack started with a ClickFix command that abused pcalua.exe to proxy mshta.exe, fetching a remote HTA file from cl.distritovagas[.]com. That HTA payload silently downloaded the MSI installer, inst24.msi, from an attacker-controlled server and executed it without any prompt.
an attacker, posing as a "System Administrator" from an external Microsoft Teams account, initiates a voice call
They cycled through AMSI patches, registry policy writes... File Path C:\ProgramData\p\ek_full.ps1 Registry-based Defender disable script
EtherRAT is a Node.js RAT that runs across Windows, Linux, and macOS, giving attackers the usual menu of post-compromise tricks: running commands, stealing data, manipulating files, and maintaining access.
The MSI deployed Potemkin into the user’s AppData folder and registered a startup registry key so it would survive every reboot. ... Registry Key HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\RunSearch Potemkin loader persistence key ... HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\EdgeUpdate EtherRAT persistence key
an attacker, posing as a "System Administrator" from an external Microsoft Teams account, initiates a voice call
EtherRAT is a Node.js RAT that runs across Windows, Linux, and macOS, giving attackers the usual menu of post-compromise tricks: running commands, stealing data, manipulating files, and maintaining access.
The MSI deployed Potemkin into the user’s AppData folder and registered a startup registry key so it would survive every reboot. ... Registry Key HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\RunSearch Potemkin loader persistence key ... HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\EdgeUpdate EtherRAT persistence key
Traditionally, defenders could disrupt attacks by seizing domains or sinkholing IP addresses; however, the integration of blockchain technology renders these methods largely obsolete. By leveraging public ledgers, threat actors have created a resilient C2 layer... | Malware families, such as EtherRAT, function by querying public Remote Procedure Call (RPC) endpoints to read state data from specific smart contracts. This allows them to resolve the latest active C2 server addresses dynamically.
Five hours later, the attacker dropped EtherRAT and set up a Cloudflare tunnel using a renamed copy of cloudflared... A reverse shell on port 43301 and multiple Chisel SOCKS tunnels gave them layered persistence
A reverse shell on port 43301 and multiple Chisel SOCKS tunnels gave them layered persistence that could survive individual detections.
Dead-Drop Resolution: Malware families, such as EtherRAT, function by querying public Remote Procedure Call (RPC) endpoints to read state data from specific smart contracts.
Once remote access is established, the attackers download and execute a malicious MSI installer that loads EtherRAT
151 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
77 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named only in a related-articles reference; no substantive discussion in the content.
Cross-platform remote access trojan used after social engineering via Microsoft Teams to gain initial access to corporate networks. It can execute commands, steal data, maintain persistence, and uses Ethereum smart contracts for command-and-control servers.
Cross-platform remote access trojan built entirely in Node.js. It is delivered via a malicious MSI installer after social engineering through Microsoft Teams, then enables command execution, file manipulation, data exfiltration, and persistence. It uses Ethereum smart contracts to retrieve its command-and-control server address, complicating takedown efforts.
A cross-platform Node.js remote access trojan that enables command execution, data theft, file manipulation, and persistent access. It retrieves an active command-and-control server from an Ethereum smart contract, with a fallback conventional domain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.