EtherRAT & SYS_INFO Module: C2 on Ethereum (EtherHiding), Target Selection, CDN-Like Beacons
2026-03-25 • e Sentire •
eSentire TRU detected EtherRAT in a retail customer environment in March 2026 and notes that Sysdig has linked the Node.js backdoor to a North Korean APT through overlaps with Contagious Interview TTPs. The observed intrusion used ClickFix to run pcalua.exe and mshta.exe, retrieve a malicious HTA from shepherdsestates[.]uk, and execute obfuscated Node.js stages that decrypted payloads with AES-256-CBC. The malware established persistence with a randomized HKCU Run value and launched EtherRAT through Node.js, enabling arbitrary command execution, host information gathering, and theft of assets such as cryptocurrency wallets and cloud credentials. EtherRAT retrieved C2 addresses from an Ethereum smart contract via public RPC providers, then blended beaconing into CDN-like HTTPS URLs, with a C2-delivered SYS_INFO module used for fingerprinting and target selection.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | shepherdsestates.uk | 2026-03-25 | 2026-03-25 |
| DOMAIN | aurineuroth.com | 2026-03-25 | 2026-03-25 |
| IPv4 | 185.218.19.162 | 2026-03-25 | 2026-03-25 |