EtherRAT & SYS_INFO Module: C2 on Ethereum (EtherHiding), Target Selection, CDN-Like Beacons

2026-03-25 e Sentire

https://www.esentire.com/blog/etherrat-sys-info-module-c2-on-ethereum-etherhiding-target-selection-cdn-like-beacons

Thumbnail for EtherRAT & SYS_INFO Module: C2 on Ethereum (EtherHiding), Target Selection, CDN-Like Beacons

eSentire TRU detected EtherRAT in a retail customer environment in March 2026 and notes that Sysdig has linked the Node.js backdoor to a North Korean APT through overlaps with Contagious Interview TTPs. The observed intrusion used ClickFix to run pcalua.exe and mshta.exe, retrieve a malicious HTA from shepherdsestates[.]uk, and execute obfuscated Node.js stages that decrypted payloads with AES-256-CBC. The malware established persistence with a randomized HKCU Run value and launched EtherRAT through Node.js, enabling arbitrary command execution, host information gathering, and theft of assets such as cryptocurrency wallets and cloud credentials. EtherRAT retrieved C2 addresses from an Ethereum smart contract via public RPC providers, then blended beaconing into CDN-like HTTPS URLs, with a C2-delivered SYS_INFO module used for fingerprinting and target selection.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN shepherdsestates.uk 2026-03-25 2026-03-25
DOMAIN aurineuroth.com 2026-03-25 2026-03-25
IPv4 185.218.19.162 2026-03-25 2026-03-25

Related Reports

« Back