Spoofed IT Tools Distribute EtherRAT in Highly Stealthy Campaign Suspected Linked to DPRK APT

2026-04-08 Phatom Candle

https://medium.com/@phatomcandle/spoofed-it-tools-distribute-etherrat-in-highly-stealthy-campaign-suspected-linked-to-dprk-apt-1aa6beab7dcb

Thumbnail for Spoofed IT Tools Distribute EtherRAT in Highly Stealthy Campaign Suspected Linked to DPRK APT

PhatomCandle tracked EtherRAT distribution through malicious MSI installers disguised as common IT administration tools, with TTP overlap to an APT group suspected of association with the DPRK. The lures targeted administrators and support personnel by spoofing utilities such as RDCMan, DelProf2, Disk2vhd, Autoruns, Procmon, Bitvise SSH Client, AzCopy, Kusto.Explorer, Autologon, and PsTools. The infection chain decrypts staged payloads using XOR or AES-CBC, installs a Node.js environment, writes a Node.js EtherRAT payload to registry AutoRun persistence, and then retrieves C2 information from Ethereum blockchain data. EtherRAT's EtherHiding approach stores active C2 server details in blockchain transactions or smart-contract storage and uses CDN-like beaconing to blend traffic and allow infrastructure rotation. Listed indicators include MD5 hashes and C2 domains such as publisherresolution[.]com, luminer[.]work, gateway001kir[.]com, solidactivate[.]com, 4apcnbr[.]microsoft[.]com, footballoff[.]com, and bermanlawrsk[.]com.

Indicators of Compromise

Type Value First Seen Last Seen
HASH cff02735bd4df3dcd917dfc187f52df2 2026-04-08 2026-04-08
HASH 31c614f72d80e1422530b8b9c6edd67f 2026-04-08 2026-04-08
HASH 4895d94d7e246ac6f4337aed761fdbce 2026-04-08 2026-04-08
HASH d45795d84bd31847f803251a8a125098 2026-04-08 2026-04-08
DOMAIN publisherresolution.com 2026-04-08 2026-04-08
DOMAIN solidactivate.com 2026-04-08 2026-04-08
DOMAIN gateway001kir.com 2026-04-08 2026-04-08
DOMAIN bermanlawrsk.com 2026-04-08 2026-04-08
DOMAIN footballoff.com 2026-04-08 2026-04-08

Related Reports

2026-04-17 • 35% Match
#Kimsuky #Phishing #T1102.002 #T1082 #T1140 #T1041 #T1113 #T1608.001 #T1071.001 #T1115 #T1083 #T1497 #T1056.001 #T1204.001 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1567 #T1057 #T1059.005 #T1583.006 #T1583.003 #T1204.004 #T1518.001 #T1568.001 #T1566.001 #T1547.001 #T1585.002 #T1056.003 #T1053.005 #T1539 #T1608.005 #T1598.003 #T1590.005 #T1583.001 #T1059.001 #T1036.005
Shares tags: T1140, T1027, T1547.001 • Published within a month
« Back