Malware
EtherRAT
According to sysdig, EtherRAT uses Ethereum smart contracts for C2 URL resolution. It establishes persistence through five independent mechanisms, ensuring survival across reboots and system maintenance (systemd, xdg, cron, bashrc, profile).
Indicators of Compromise 5
MITRE ATT&CK TTPs 15
T1027 T1055.012 T1059.001 T1059.007 T1071.001 T1078 T1085 T1133 T1202 T1204.002 T1212 T1484.001 T1548 T1558.003 T1566
Obfuscated Files or Information
Defense Evasion
Process Hollowing
Defense Evasion
PowerShell
Execution
JavaScript
Execution
Web Protocols
Command And Control
Valid Accounts
Defense Evasion
T1085
External Remote Services
Persistence
Indirect Command Execution
Defense Evasion
Malicious File
Execution
Exploitation for Credential Access
Credential Access
Group Policy Modification
Defense Evasion
Abuse Elevation Control Mechanism
Privilege Escalation
Kerberoasting
Credential Access
Phishing
Initial Access
Source Articles
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories
This week's threat landscape highlights a range of cyber activities, from cloud bucket hijacking and ransomware tooling overlaps to social engineering campaigns and supply chain attacks. Notable incidents include a global fraud operation resulting in nearly 6,000 arrests, typosquatting of payment SDKs on npm and PyPI, and the abuse of Microsoft Teams for delivering EtherRAT. Additionally, new techniques like Process Parameter Poisoning and ADFS token forgery underscore evolving evasion and privilege escalation methods.
hacker-news ·2w ago
Fake IT support calls on Microsoft Teams push EtherRAT malware
Threat actors are conducting fake IT support calls via Microsoft Teams to trick employees into installing the EtherRAT malware. The attack begins with a phishing email containing a malicious PDF, followed by a voice call from an external Teams account impersonating system administrators. Attackers use legitimate remote access tools like HopToDesk and AnyDesk, then deploy EtherRAT via a malicious MSI installer, enabling full system control and data theft. EtherRAT uses Ethereum smart contracts for C2 resilience, and the campaign is actively evolving with multiple malware versions observed.
bleeping-computer ·3w ago