EtherRAT & SYS_INFO Module: C2 on Ethereum (EtherHiding), Target Selection, CDN-Like Beacons
Essential information
- Published
- 26/03/2026 21:08
- Modified
- 27/03/2026 00:17
- Tags
- 2026-03-26 backdoor cdn-like beaconing cis language check ethereum etherhiding etherrat host fingerprinting it support scams node.js sys_info module
- Related entities
- 10 observables, 1 intrusion sets (apt), 18 techniques (mitre), 1 malware, 16 others
Description
EtherRAT, a Node.js-based backdoor linked to a North Korean APT group, was detected in a retail customer's environment. It allows arbitrary command execution, extensive system information gathering, and asset theft. The malware uses 'EtherHiding' to store C2 addresses in Ethereum smart contracts, making infrastructure resilient to takedowns. It communicates using CDN-like beaconing to blend with normal traffic. Initial access varied, including ClickFix and IT Support scams via Microsoft Teams. A SYS_INFO module performs comprehensive host fingerprinting for target selection. The malware checks for CIS languages and self-destructs if found. It collects detailed system information, including hardware, software, and network details.