HomeSecurityEtherRAT pretends to be management tools via fake profiles on GitHub

EtherRAT pretends to be management tools via fake profiles on GitHub

A sophisticated and persistent malware campaign (EtherRAT) was detected by the Atos Threat Research Center (TRC) in March 2026. This operation specifically targets the highly privileged professional accounts of business administrators, DevOps engineers, and security analysts, impersonating the administrative tools they rely on for their daily operations. By incorporating search engine optimization (SEO) poisoning, a two-stage distribution architecture via GitHub, and decentralized command and control (C2) resolution based on blockchain, the malicious actors have created a highly resilient delivery and persistence mechanism.

See also: GitHub fixed critical RCE vulnerability in less than 6 hours

EtherRAT

The campaign uses a multi-layered delivery chain designed to evade platform-level takedowns and maintain high search engine rankings. The attack begins with SEO poisoning on various search engines, including Bing, Yahoo, DuckDuckGo, and Yandex, ensuring that malicious results for specialized IT terms rank at the top of search results.

Users are initially directed to a primary repository on GitHub, which is optimized for SEO but contains no malicious code – just a professional README file.

To maintain operational flexibility, the README contains a link that directs the victim to a second, hidden GitHub repository, which acts as the actual distribution point for the malware. By separating the SEO-optimized storefront from the payload delivery account, malicious actors can quickly rotate their distribution repositories if they are flagged, while the primary search-indexed frontend remains active and untouched.

See also: Critical vulnerability in GitHub – Exploited via Git Push

EtherRAT pretends to be management tools via fake profiles on GitHub

The campaign is characterized by its focus on the administrative stack. By distributing malicious MSI installers disguised as tools such as PsExec, AzCopy, Sysmon, LAPS , and Kusto Explorer, the adversary performs automated profiling of victims. These tools are used almost exclusively by personnel with elevated network and system privileges. A successful infection of an administrator’s computer can provide the “keys to the kingdom,” facilitating lateral movement within the enterprise environment.

The most technically significant element of the campaign is the implementation of Blockchain-based Decentralized Dead Drop Resolution (DDR). Once the malicious MSI is executed, the malware does not communicate with a hardcoded domain or IP address, which could be easily blocked. Instead, the malware repeatedly initiates a query to a public Ethereum (ETH) RPC point.

See also: Checkmarx: Data from GitHub repository on the dark web

EtherRAT pretends to be management tools via fake profiles on GitHub

The malware is hardcoded with a specific Smart Contract address on the Ethereum blockchain. By querying this contract, the malware dynamically retrieves the live address of the C2 server. This technique provides the adversary with exceptional resilience:

  • Infrastructure flexibility: The attacker can rotate C2 servers worldwide simply by updating the value stored in the blockchain contract.
  • Resilience: As long as Ethereum's public portals are accessible, malware can always find its home, rendering traditional domain removal or blocking efforts ineffective.
Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS