#etherrat

[ follow ]
fromBleepingComputer
15 hours ago

North Korean hackers exploit React2Shell flaw in EtherRAT malware attacks

A new malware implant called EtherRAT, deployed in a recent React2Shell attack, runs five separate Linux persistence mechanisms and leverages Ethereum smart contracts for communication with the attacker. Researchers at cloud security company Sysdig believe that the malware aligns with North Korea's tools used in Contagious Interview campaigns. They recovered EtherRAT from a compromised Next.js application just two days after the disclosure of the critical React2Shell vulnerability tracked as CVE-2025-55182.
Information security
Information security
fromThe Hacker News
15 hours ago

North Korea-linked Actors Exploit React2Shell to Deploy New EtherRAT Malware

North Korea-linked actors exploited the React2Shell RSC vulnerability to deploy EtherRAT, a Node.js-based RAT that uses Ethereum smart contracts for command-and-control.
[ Load more ]