EtherRAT Malware Recently Identified Combining Credential Theft and Cryptocurrency Wallet Attacks

According to LevelBlue SpiderLabs researchers, EtherRAT, a recently identified malware, combines credential theft, remote access, and cryptocurrency wallet attacks in a single coordinated campaign. The malware is distributed through fake Tftpd64 installers hosted on fraudulent GitHub repositories designed to mimic the legitimate TFTP server utility. The malware bundle includes multiple Ethereum RPC endpoints associated with Flashbots, Tenderly, LlamaRPC, and DRPC, along with Ethereum wallet addresses, enabling attackers to conduct blockchain interactions and facilitate cryptocurrency asset theft. Researchers warned that the campaign targets IT administrators and network professionals, as trusted administrative tools attract less scrutiny from security systems.
Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments