HomeSecurityNorth Korean hackers exploit React2Shell to develop EtherRAT

North Korean hackers exploit React2Shell to deploy EtherRAT

Hackers linked to North Korea may have exploited the recently disclosed React2Shell in React Server Components (RSC) to deliver a previously undisclosed remote access Trojan dubbed EtherRAT.

See also: Lazarus' new ScoringMathTea RAT allows remote command execution

React2Shell EtherRAT
North Korean hackers exploit React2Shell to deploy EtherRAT

According to a report by Sysdig, EtherRAT leverages Ethereum smart contracts to resolve command and control (C2), deploys five independent persistence mechanisms on Linux, and downloads its own Node.js from nodejs.org.

The cloud security firm noted that the activity shows significant overlap with a long-running campaign codenamed Contagious Interview, which has been observed using the EtherHiding to distribute malware since February 2025.

The Contagious Interview campaign refers to a series of attacks targeting blockchain and Web3 developers through fake job interviews, coding assignments, and video assessments, leading to the development of malware. These efforts typically begin with a scam that lures victims through platforms like LinkedIn, Upwork , or Fiverr, where hackers pretend to offer attractive job opportunities.

According to software supply chain security firm Socket, this is one of the most prolific campaigns exploiting the npm ecosystem, highlighting their ability to adapt to workflows focused on JavaScript and cryptocurrencies.

The attack chain begins by exploiting CVE-2025-55182 (CVSS score: 10.0), a maximum severity security vulnerability in RSC, to execute a Base64-encoded shell command that downloads and executes a shell script responsible for deploying the main JavaScript implant.

See also: Australia: Sanctions on hackers supporting North Korea's weapons program

North Korean hackers exploit React2Shell to deploy EtherRAT

The shell script is retrieved using a curl command, with wget and python3 being used as alternatives. It is designed to prepare the environment by downloading Node.js v20.10.0 from nodejs.org, after which it writes an encrypted blob and a cloaked JavaScript dropper to disk. Once these steps are complete, it deletes the shell script to minimize the forensic trail and executes the dropper.

The main goal of the dropper is to decrypt the EtherRAT payload with a hardcoded key and launch it using the downloaded Node.js binary. The malware is notable for using EtherHiding to retrieve the C2 server URL from an Ethereum smart contract every five minutes, allowing operators to easily update the URL even if it is removed.

A similar implementation was previously observed in two npm packages named colortoolsv2 and mimelib2 that were found to deliver malicious downloader software to developers' systems.

Once EtherRAT establishes contact with the C2 server, it enters a control loop that runs every 500 milliseconds, interpreting any response longer than 10 characters as JavaScript code to be executed on the infected machine . Persistence is achieved using five different methods, including a Systemd user service .

Using multiple mechanisms, hackers can ensure that the malware runs even after a system reboot, giving them continued access to infected systems. Another sign of the malware’s sophistication is its ability to self-update, replacing itself with new code obtained from the C2 server after sending its own source code to an API point.

See also: Lazarus hackers targeted European defense companies

North Korean hackers exploit React2Shell to deploy EtherRAT

It then starts a new process with the updated payload. Notably, the C2 server returns a functionally identical but differently disguised version, possibly allowing it to bypass detection.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS