TF-MAL-js.ether_rat
📛 Threat Title
Malware family: EtherRAT
Description
ThreatFox malware family `js.ether_rat`. Printable name: EtherRAT.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:atos.net
The Sysdig Threat Research Team has previously linked this malware to the North Korean state-sponsored actor - Lazarus Group. They noticed significant overlaps in the tooling utilized during operations conducted with the usage of EtherRAT and the " Contagious Interview " campaign.
-
web:cybersecsentinel.com
Persistence Mechanisms The Aggressive Five EtherRAT uses five overlapping persistence techniques. All must be checked and cleared during remediation . Table 2 EtherRAT persistence vectors ... The malware also tracks persistence state locally to avoid writing duplicate entries, which reduces noisy errors and makes manual inspection harder.
-
web:cybersecuritynews.com
A novel, highly sophisticated malware strain targeting vulnerable React Server Components, signaling a significant evolution in how state-sponsored threat actors are exploiting the critical React2Shell vulnerability disclosed just days earlier.
-
web:malpedia.caad.fkie.fraunhofer.de
According to sysdig, EtherRAT uses Ethereum smart contracts for C2 URL resolution. It establishes persistence through five independent mechanisms, ensuring survival across reboots and system maintenance (systemd, xdg, cron, bashrc, profile).
-
web:thedfirreport.com
The EtherRAT malware family was first reported by Sysdig back in December 2025. At that time, the initial access vector was exploitation of CVE-2025-55182 (React2Shell) targeting Linux servers. In March 2026, a Windows variant campaign was reported by Atos, with their investigation showing evidence of activity going back to the previous December.
-
web:thehackernews.com
North Korea-linked attackers exploit CVE-2025-55182 to deploy EtherRAT , a smart-contract-based RAT with multi-stage persistence.
-
web:www.bleepingcomputer.com
A new malware implant called EtherRAT , deployed in a recent React2Shell attack, runs five separate Linux persistence mechanisms and leverages Ethereum smart contracts for communication with the ...
-
web:www.cybersecurityintelligence.com
Security researchers at Sysdig have identified a sophisticated malware campaign exploiting the critical React2Shell vulnerability (CVE-2025-55182), disclosed on 3 December 2025. Just two days later, on 5 December 2025, the Sysdig Threat Research Team recovered a novel implant, dubbed EtherRAT , from a compromised Next.js application.
-
web:www.microsoft.com
CVE-2025-55182 (also referred to as React2Shell and includes CVE-2025-66478, which was merged into it) is a critical pre-authentication remote code execution (RCE) vulnerability affecting React Server Components and related frameworks.
-
web:www.sysdig.com
Discover how the critical React2Shell vulnerability (CVE-2025-55182) is being actively exploited to deploy EtherRAT , a persistent access implant that uses Ethereum smart contracts for blockchain C2 and multi-layer Linux persistence.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.