EtherRAT
malware · malware:etherrat single-source
Node.js remote-access trojan targeting Windows workstations via social engineering and Linux servers via exploitation of server-side vulnerabilities, retrieving its command-and-control URL from a predefined smart contract through public Ethereum RPC endpoints; modules cover credential theft, lateral movement and web-server hijacking (Red Canary, 2026-08-20). Microsoft's own Defender detection signatures for a mechanistically overlapping Node.js/Ethereum-smart-contract implant read Trojan:JS/EtherRatz.A!MTB / .B!MTB (Microsoft Threat Intelligence, 2026-09-02), Microsoft's own reporting never uses the name EtherRAT, so EtherRatz is carried here as an alias reflecting the overlap, not a vendor-confirmed identity.
Aliases: EtherRatz
Coverage
4
2 about it · 2 mentions · first 2026-05-29 → last 2026-09-03
Latest activity
2026-09-03
The intrusion's most consequential step is a remote-management connection from a non-administrative process…
Peak priority
high
1 high · 1 notable
Targets
public-sector
sectors: public-sector, finance, telco · regions: europe
Sources cited
9
7 hosts
Action items (3)
Do-now tasks recorded on the entries about EtherRAT, newest first. Check the date before acting on an older one.
- Restrict inbound Microsoft Teams external collaboration to a vetted allow-list of domains, or require explicit user opt-in per external organisation, given the campaign's initial-access channel is unsolicited Teams chats/calls impersonating internal IT support.2026-09-03The intrusion's most consequential step is a…
- Restrict WinRM (TCP 5985) inbound to domain controllers and certificate authorities to a small, known set of administrative source hosts; the campaign's lateral-movement step specifically relies on WinRM being reachable from ordinary workstations to these systems.2026-09-03The intrusion's most consequential step is a…
- Establish which users, systems and applications in your estate legitimately make HTTPS calls to public blockchain RPC endpoints (for most public-sector estates the honest answer is none) and alert on anything outside that set; chainlist.org enumerates the widely-used endpoints adversaries prefer.2026-08-23Dead-drop C2 moved from novelty to routine, and the…
Defender insights
What each entry about EtherRAT tells a defender to do, newest first.
Triage
Triage
Story timeline
Every entry that names EtherRAT, newest first. Rows tagged mention only name it in passing: they are listed for completeness and add nothing to the action items, pivots or ATT&CK profile on this page.
- 2026-09-03A Teams helpdesk-impersonation campaign installs a Node.js implant (Microsoft detection name: EtherRatz) via a silent MSI, then pivots over WinRM straight to domain controllers and certificate authorities
- 2026-08-23Dead-drop command-and-control went commodity: three of four new entrants on Red Canary's monthly list resolve their C2 from a dead drop, two of them from a public blockchain, and the fourth is a GUI for Entra ID device-code phishing
- 2026-06-17Huntress: Potemkin loader delivers RMMProject RAT and bypasses Chromium App-Bound Encryption
- 2026-05-29The Gentlemen ransomware, Microsoft publishes full technical dissection of the Storm-2697 Go-encryptor
Hunting pivots
ATT&CK techniques (21 across 11 tactics)
21 techniques observed across 2 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessPhishing: Spearphishing via Service
- ExecutionCommand and Scripting Interpreter: PowerShell · Command and Scripting Interpreter: JavaScript · User Execution: Malicious Copy and Paste
- PersistenceCreate or Modify System Process: Launch Agent · Modify Authentication Process: Multi-Factor Authentication
- Privilege EscalationCreate or Modify System Process: Launch Agent
- StealthMasquerading · System Binary Proxy Execution: Msiexec · System Binary Proxy Execution: Rundll32 · Virtualization/Sandbox Evasion: System Checks
- Defense ImpairmentModify Authentication Process: Multi-Factor Authentication
- Credential AccessSteal Application Access Token · Modify Authentication Process: Multi-Factor Authentication
- DiscoverySystem Network Configuration Discovery · Remote System Discovery · System Information Discovery · Account Discovery: Domain Account · Virtualization/Sandbox Evasion: System Checks · Software Discovery: Security Software Discovery
- Lateral MovementRemote Services: Windows Remote Management
- CollectionScreen Capture
- Command and ControlApplication Layer Protocol: Web Protocols · Web Service: Dead Drop Resolver · Ingress Tool Transfer
Initial Access TA0001
T1566.003Phishing: Spearphishing via Service×1
Adversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems. Spearphishing via service is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of third party services rather than directly via enterprise email channels.
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · ATT&CK page ↗
Execution TA0002
T1059.001Command and Scripting Interpreter: PowerShell×1
Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · ATT&CK page ↗
T1059.007Command and Scripting Interpreter: JavaScript×1
Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · ATT&CK page ↗
T1204.004User Execution: Malicious Copy and Paste×1
An adversary may rely upon a user copying and pasting code in order to gain execution. Users may be subjected to social engineering to get them to copy and paste code directly into a Command and Scripting Interpreter. One such strategy is "ClickFix," in which adversaries present users with seemingly helpful solutions (such as prompts to fix errors or complete CAPTCHAs) that instead instruct the user to copy and paste malicious code.
Evidence: 2026-08-23/blockchain-dead-drop-c2-commodity-graphspy · ATT&CK page ↗
Persistence TA0003
T1543.001Create or Modify System Process: Launch Agent×1
Adversaries may create or modify launch agents to repeatedly execute malicious payloads as part of persistence. When a user logs in, a per-user launchd process is started which loads the parameters for each launch-on-demand user agent from the property list (.plist) file found in <code>/System/Library/LaunchAgents</code>, <code>/Library/LaunchAgents</code>, and <code>~/Library/LaunchAgents</code>. Property list files use the <code>Label</code>, <code>ProgramArguments </code>, and <code>RunAtLoad</code> keys to identify the Launch Agent's name, executable location, and execution time. Launch Agents are often installed to perform updates to programs, launch user specified programs at login, or to conduct other developer tasks.
Evidence: 2026-08-23/blockchain-dead-drop-c2-commodity-graphspy · ATT&CK page ↗
T1556.006Modify Authentication Process: Multi-Factor Authentication×1
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-08-23/blockchain-dead-drop-c2-commodity-graphspy · ATT&CK page ↗
Privilege Escalation TA0004
T1543.001Create or Modify System Process: Launch Agent×1
Adversaries may create or modify launch agents to repeatedly execute malicious payloads as part of persistence. When a user logs in, a per-user launchd process is started which loads the parameters for each launch-on-demand user agent from the property list (.plist) file found in <code>/System/Library/LaunchAgents</code>, <code>/Library/LaunchAgents</code>, and <code>~/Library/LaunchAgents</code>. Property list files use the <code>Label</code>, <code>ProgramArguments </code>, and <code>RunAtLoad</code> keys to identify the Launch Agent's name, executable location, and execution time. Launch Agents are often installed to perform updates to programs, launch user specified programs at login, or to conduct other developer tasks.
Evidence: 2026-08-23/blockchain-dead-drop-c2-commodity-graphspy · ATT&CK page ↗
Stealth TA0005
T1036Masquerading×1
Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names.
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · ATT&CK page ↗
T1218.007System Binary Proxy Execution: Msiexec×1
Adversaries may abuse msiexec.exe to proxy execution of malicious payloads. Msiexec.exe is the command-line utility for the Windows Installer and is thus commonly associated with executing installation packages (.msi). The Msiexec.exe binary may also be digitally signed by Microsoft.
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · ATT&CK page ↗
T1218.011System Binary Proxy Execution: Rundll32×1
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations. Rundll32.exe is commonly associated with executing DLL payloads (ex: <code>rundll32.exe {DLLname, DLLfunction}</code>).
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · ATT&CK page ↗
T1497.001Virtualization/Sandbox Evasion: System Checks×1
Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · ATT&CK page ↗
Defense Impairment TA0112
T1556.006Modify Authentication Process: Multi-Factor Authentication×1
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-08-23/blockchain-dead-drop-c2-commodity-graphspy · ATT&CK page ↗
Credential Access TA0006
T1528Steal Application Access Token×1
Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.
Evidence: 2026-08-23/blockchain-dead-drop-c2-commodity-graphspy · ATT&CK page ↗
T1556.006Modify Authentication Process: Multi-Factor Authentication×1
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-08-23/blockchain-dead-drop-c2-commodity-graphspy · ATT&CK page ↗
Discovery TA0007
T1016System Network Configuration Discovery×1
Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems. Several operating system administration utilities exist that can be used to gather this information. Examples include Arp, ipconfig/ifconfig, nbtstat, and route.
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · ATT&CK page ↗
T1018Remote System Discovery×1
Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system. Functionality could exist within remote access tools to enable this, but utilities available on the operating system could also be used such as Ping, <code>net view</code> using Net, or, on ESXi servers, `esxcli network diag ping`.
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · ATT&CK page ↗
T1082System Information Discovery×1
An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes.
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · ATT&CK page ↗
T1087.002Account Discovery: Domain Account×1
Adversaries may attempt to get a listing of domain accounts. This information can help adversaries determine which domain accounts exist to aid in follow-on behavior such as targeting specific accounts which possess particular privileges.
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · ATT&CK page ↗
T1497.001Virtualization/Sandbox Evasion: System Checks×1
Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · ATT&CK page ↗
T1518.001Software Discovery: Security Software Discovery×1
Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment. This may include things such as cloud monitoring agents and anti-virus. Adversaries may use the information from Security Software Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · ATT&CK page ↗
Lateral Movement TA0008
T1021.006Remote Services: Windows Remote Management×1
Adversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM). The adversary may then perform actions as the logged-on user.
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · ATT&CK page ↗
Collection TA0009
T1113Screen Capture×1
Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as <code>CopyFromScreen</code>, <code>xwd</code>, or <code>screencapture</code>.
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · ATT&CK page ↗
Command and Control TA0011
T1071.001Application Layer Protocol: Web Protocols×1
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · ATT&CK page ↗
T1102.001Web Service: Dead Drop Resolver×1
Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers.
Evidence: 2026-08-23/blockchain-dead-drop-c2-commodity-graphspy · ATT&CK page ↗
T1105Ingress Tool Transfer×1
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).
Evidence: 2026-09-03/teams-helpdesk-impersonation-nodejs-implant-winrm-dc-pivot · ATT&CK page ↗
Entries about EtherRAT (2)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- CastleRAT×1
- GraphSpy×1
- Microsoft 365×1
- Microsoft Entra ID×1
- Microsoft Teams×1
- Phexia×1
- SynkLoader×1
- The Gentlemen×1
Where this entity is cited
Source distribution
- huntress.com2 (22%)
- microsoft.com2 (22%)
- learn.microsoft.com1 (11%)
- redcanary.com1 (11%)
- research.checkpoint.com1 (11%)
- thedfirreport.com1 (11%)
- thehackernews.com1 (11%)
All cited sources (9)
- huntress.comHuntress, 2026-06-16https://www.huntress.com/blog/potemkin-loader-rmmproject-clickfix-attack
- huntress.comHuntress Labshttps://www.huntress.com/blog/the-gentlemen-ransomware-defense-evasion-ttps
- learn.microsoft.comASR rules referencehttps://learn.microsoft.com/en-us/defender-endpoint/attack-surface-reduction-rules-reference
- microsoft.comMicrosoft Threat Intelligence, The Gentlemen dissectionhttps://www.microsoft.com/en-us/security/blog/2026/05/28/the-gentlemen-ransomware-dissecting-a-self-propagating-go-encryptor/
- microsoft.comMicrosoft Threat Intelligencehttps://www.microsoft.com/en-us/security/blog/2026/09/02/impersonating-it-support-threat-actors-turn-remote-session-into-enterprise-wide-access/
- redcanary.comRed Canaryhttps://redcanary.com/blog/threat-intelligence/intelligence-insights-august-2026/
- research.checkpoint.comCheck Point Researchhttps://research.checkpoint.com/2026/thus-spoke-the-gentlemen/
- thedfirreport.comThe DFIR Report, flash alerthttps://thedfirreport.com/2026/05/11/flash-alert-etherrat-and-tuktuk-c2-end-in-the-gentleman-ransomware/
- thehackernews.comThe Hacker News, 2026-06-16https://thehackernews.com/2026/06/clickfix-campaigns-expand-malware.html