North Korean Hackers Unleash EtherRAT: The Trojan that’s Smarter than Your Average RAT

North Korea-linked hackers are exploiting the React2Shell flaw to release EtherRAT, a persistent remote access trojan with Ethereum smart contracts. This malware blends North Korean tactics but ditches credential theft for long-term stealth, forcing defenders to face a new, cunning adversary.

Pro Dashboard

Hot Take:

When North Korea isn’t busy launching rockets, they’re launching cyberattacks. The latest in their digital arsenal? EtherRAT—because why settle for one RAT when you can have the whole infestation? Someone needs to tell these hackers that borrowing from Ethereum to build a smart contract C2 is like bringing a bazooka to a pillow fight. But hey, who doesn’t love a good blockchain twist?

Key Points:

  • North Korean hackers are exploiting the React2Shell vulnerability (CVE-2025-55182) to deploy the newly discovered EtherRAT.
  • EtherRAT is a remote access trojan that uses Ethereum smart contracts for command and control (C2).
  • The attack involves sophisticated social engineering tactics, targeting developers in crypto and Web3 fields.
  • EtherRAT’s persistence is achieved through multiple Linux methods and blockchain-based C2, making it hard to detect.
  • Attribution is uncertain, but there’s significant overlap with previous North Korean campaigns, particularly the “Contagious Interview.”

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?