s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-js.ether_rat

📛 Threat Title

Malware family: EtherRAT

Category: EtherRAT First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `js.ether_rat`. Printable name: EtherRAT.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:atos.net

    The Sysdig Threat Research Team has previously linked this malware to the North Korean state-sponsored actor - Lazarus Group. They noticed significant overlaps in the tooling utilized during operations conducted with the usage of EtherRAT and the " Contagious Interview " campaign.

  • web:cybersecsentinel.com

    Persistence Mechanisms The Aggressive Five EtherRAT uses five overlapping persistence techniques. All must be checked and cleared during remediation . Table 2 EtherRAT persistence vectors ... The malware also tracks persistence state locally to avoid writing duplicate entries, which reduces noisy errors and makes manual inspection harder.

  • web:cybersecuritynews.com

    A novel, highly sophisticated malware strain targeting vulnerable React Server Components, signaling a significant evolution in how state-sponsored threat actors are exploiting the critical React2Shell vulnerability disclosed just days earlier.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to sysdig, EtherRAT uses Ethereum smart contracts for C2 URL resolution. It establishes persistence through five independent mechanisms, ensuring survival across reboots and system maintenance (systemd, xdg, cron, bashrc, profile).

  • web:thedfirreport.com

    The EtherRAT malware family was first reported by Sysdig back in December 2025. At that time, the initial access vector was exploitation of CVE-2025-55182 (React2Shell) targeting Linux servers. In March 2026, a Windows variant campaign was reported by Atos, with their investigation showing evidence of activity going back to the previous December.

  • web:thehackernews.com

    North Korea-linked attackers exploit CVE-2025-55182 to deploy EtherRAT , a smart-contract-based RAT with multi-stage persistence.

  • web:www.bleepingcomputer.com

    A new malware implant called EtherRAT , deployed in a recent React2Shell attack, runs five separate Linux persistence mechanisms and leverages Ethereum smart contracts for communication with the ...

  • web:www.cybersecurityintelligence.com

    Security researchers at Sysdig have identified a sophisticated malware campaign exploiting the critical React2Shell vulnerability (CVE-2025-55182), disclosed on 3 December 2025. Just two days later, on 5 December 2025, the Sysdig Threat Research Team recovered a novel implant, dubbed EtherRAT , from a compromised Next.js application.

  • web:www.microsoft.com

    CVE-2025-55182 (also referred to as React2Shell and includes CVE-2025-66478, which was merged into it) is a critical pre-authentication remote code execution (RCE) vulnerability affecting React Server Components and related frameworks.

  • web:www.sysdig.com

    Discover how the critical React2Shell vulnerability (CVE-2025-55182) is being actively exploited to deploy EtherRAT , a persistent access implant that uses Ethereum smart contracts for blockchain C2 and multi-layer Linux persistence.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.