Spoofed IT Tools Distribute EtherRAT in Highly Stealthy Campaign Suspected Linked to DPRK APT
2026-04-08 • Phatom Candle •
PhatomCandle tracked EtherRAT distribution through malicious MSI installers disguised as common IT administration tools, with TTP overlap to an APT group suspected of association with the DPRK. The lures targeted administrators and support personnel by spoofing utilities such as RDCMan, DelProf2, Disk2vhd, Autoruns, Procmon, Bitvise SSH Client, AzCopy, Kusto.Explorer, Autologon, and PsTools. The infection chain decrypts staged payloads using XOR or AES-CBC, installs a Node.js environment, writes a Node.js EtherRAT payload to registry AutoRun persistence, and then retrieves C2 information from Ethereum blockchain data. EtherRAT's EtherHiding approach stores active C2 server details in blockchain transactions or smart-contract storage and uses CDN-like beaconing to blend traffic and allow infrastructure rotation. Listed indicators include MD5 hashes and C2 domains such as publisherresolution[.]com, luminer[.]work, gateway001kir[.]com, solidactivate[.]com, 4apcnbr[.]microsoft[.]com, footballoff[.]com, and bermanlawrsk[.]com.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | cff02735bd4df3dcd917dfc187f52df2 | 2026-04-08 | 2026-04-08 |
| HASH | 31c614f72d80e1422530b8b9c6edd67f | 2026-04-08 | 2026-04-08 |
| HASH | 4895d94d7e246ac6f4337aed761fdbce | 2026-04-08 | 2026-04-08 |
| HASH | d45795d84bd31847f803251a8a125098 | 2026-04-08 | 2026-04-08 |
| DOMAIN | publisherresolution.com | 2026-04-08 | 2026-04-08 |
| DOMAIN | solidactivate.com | 2026-04-08 | 2026-04-08 |
| DOMAIN | gateway001kir.com | 2026-04-08 | 2026-04-08 |
| DOMAIN | bermanlawrsk.com | 2026-04-08 | 2026-04-08 |
| DOMAIN | footballoff.com | 2026-04-08 | 2026-04-08 |