Malware
EtherRAT
According to sysdig, EtherRAT uses Ethereum smart contracts for C2 URL resolution. It establishes persistence through five independent mechanisms, ensuring survival across reboots and system maintenance (systemd, xdg, cron, bashrc, profile).
Indicators of Compromise 15
Domain arweave[.]net Domain camorreado[.]click Domain camorreado[[.]]click Domain nodejs[.]org Filename .cursorrules Filename AccountGuard.zip Filename CLAUDE.md Filename ClickFix overlay Filename v7.msi GitHub Repo Hunt.io GitHub Repo SecFlow GitHub Repo unit42/poc GitHub User Hunt.io IP 193[.]233[.]202[.]17 Registry User [email protected][.]com
MITRE ATT&CK TTPs 40
T1016 T1021.001 T1027 T1053.005 T1055 T1055.012 T1056.003 T1059 T1059.001 T1059.007 T1070.004 T1071.001 T1071.004 T1074.001 T1078 T1080 T1082 T1085 T1087.002 T1090.004 T1095 T1098.004 T1105 T1113 T1133 T1202 T1204.002 T1210 T1212 T1484.001 T1484.002 T1485 T1490 T1496 T1548 T1555 T1557.001 T1558.003 T1566 T1647
System Network Configuration Discovery
Discovery
Remote Desktop Protocol
Lateral Movement
Obfuscated Files or Information
Defense Evasion
Scheduled Task
Execution
Process Injection
Defense Evasion
Process Hollowing
Defense Evasion
Web Portal Capture
Collection
Command and Scripting Interpreter
Execution
PowerShell
Execution
JavaScript
Execution
File Deletion
Defense Evasion
Web Protocols
Command And Control
DNS
Command And Control
Local Data Staging
Collection
Valid Accounts
Defense Evasion
Taint Shared Content
Lateral Movement
System Information Discovery
Discovery
T1085
Domain Account
Discovery
Domain Fronting
Command And Control
Non-Application Layer Protocol
Command And Control
SSH Authorized Keys
Persistence
Ingress Tool Transfer
Command And Control
Screen Capture
Collection
External Remote Services
Persistence
Indirect Command Execution
Defense Evasion
Malicious File
Execution
Exploitation of Remote Services
Lateral Movement
Exploitation for Credential Access
Credential Access
Group Policy Modification
Defense Evasion
Trust Modification
Defense Evasion
Data Destruction
Impact
Inhibit System Recovery
Impact
Resource Hijacking
Impact
Abuse Elevation Control Mechanism
Privilege Escalation
Credentials from Password Stores
Credential Access
LLMNR/NBT-NS Poisoning and SMB Relay
Credential Access
Kerberoasting
Credential Access
Phishing
Initial Access
Plist File Modification
Defense Evasion
Source Articles
ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories
A Chinese-speaking threat actor is leveraging AI models like Anthropic Claude, Alibaba Qwen, and DeepSeek to automate cyber intrusions against government and financial systems in multiple countries, including Taiwan, Afghanistan, Thailand, and the U.S. The campaign uses an AI orchestration framework called SecFlow to divide tasks among specialized AI agents for reconnaissance, exploitation, and data collection. Exploited vulnerabilities include Log4Shell, Spring4Shell, and Shiro deserialization, leading to web shell deployment and lateral movement using a Go-based backdoor named SecBox. The campaign was first reported in July 2026. Another related campaign involves EtherRAT and TukTuk malware, where attackers deploy ransomware known as The Gentlemen after gaining access via malicious MSI installers and conducting credential theft and lateral movement.
hacker-news ·1d ago
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
Threat actors are leveraging the legitimate Node.js runtime (node.exe) to deliver malware in targeted attacks against government departments, technology firms, and hotels since February 2026. By using signed, trusted binaries and executing malicious JavaScript scripts, attackers evade signature-based detection. The attacks involve tools such as AdaptixC2, Cobalt Strike, ModeloRAT, Mistic (MLTBackdoor), GateKeeper, and C2Looper, with initial access often gained via the ClickFix social engineering technique. Attackers also abuse EtherHiding and blockchain-based C2 infrastructure for resilience, making blocking efforts difficult.
hacker-news ·1w ago
ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories
Multiple active threat campaigns were reported, including a new SideWinder attack chain using ClickOnce files to deploy Rust-based backdoors, a large-scale npm supply chain attack named 'Flooding Dropper' involving 846 malicious packages, and a Chinese threat actor leveraging a DeepSeek AI agent in an LLM-managed campaign for proxyjacking. A new XCSSET macOS malware variant (v40) spreads via compromised Xcode projects and includes a Telegram trojanizer. The Gentlemen ransomware affiliate deployed EtherRAT, which retrieves C2 data from an Ethereum smart contract. Additionally, Interlock ransomware abused Volatility3 to extract credentials from memory, and a critical RCE flaw in the Odysseus AI workspace allowed authenticated users to execute OS commands. Several phishing campaigns used fake Bank of America and Coldcard wallet lures to install ScreenConnect, while AI-powered scam farms like FunFoneFarm lower the barrier to entry for cybercrime.
hacker-news ·1mo ago
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories
This week's threat landscape highlights a range of cyber activities, from cloud bucket hijacking and ransomware tooling overlaps to social engineering campaigns and supply chain attacks. Notable incidents include a global fraud operation resulting in nearly 6,000 arrests, typosquatting of payment SDKs on npm and PyPI, and the abuse of Microsoft Teams for delivering EtherRAT. Additionally, new techniques like Process Parameter Poisoning and ADFS token forgery underscore evolving evasion and privilege escalation methods.
hacker-news ·2mo ago
Fake IT support calls on Microsoft Teams push EtherRAT malware
Threat actors are conducting fake IT support calls via Microsoft Teams to trick employees into installing the EtherRAT malware. The attack begins with a phishing email containing a malicious PDF, followed by a voice call from an external Teams account impersonating system administrators. Attackers use legitimate remote access tools like HopToDesk and AnyDesk, then deploy EtherRAT via a malicious MSI installer, enabling full system control and data theft. EtherRAT uses Ethereum smart contracts for C2 resilience, and the campaign is actively evolving with multiple malware versions observed.
bleeping-computer ·2mo ago