216.73.216.226

EtherRAT Targeting Windows Disguised as a Game Mod Installer

· Published 21/01/2026 12:36 · Modified 21/01/2026 23:18

Export JSON

Essential information

Published
21/01/2026 12:36
Modified
21/01/2026 23:18
Tags
123 stealer 2026-01-21 CVE-2025-55182 c2 communication ethereum etherrat game mod msi obfuscation persistence smart-contract tsundere botnet windows
Related entities
12 observables, 14 techniques (mitre), 3 malware, 5 others

Description

A variant of , a JavaScript-based malware, has been discovered disguised as installers. The malware uses files to create and execute obfuscated scripts that decrypt and run the main payload. retrieves its Command and Control (C2) server addresses dynamically through smart contracts, employing anti-analysis techniques and establishing via Registry Run keys. The malware's infrastructure has been linked to the , sharing C2 servers and smart contract similarities. Analysis revealed multiple contract addresses and wallet addresses associated with the attacker, indicating an expanding and evolving operation targeting both and Linux systems.

External references