Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
EtherRAT Malware Targets Windows via Trojanized Installer

EtherRAT Malware Targets Windows via Trojanized Installer

Posted on April 30, 2026 By CWS

A newly detected malware variant, EtherRAT, is threatening Windows users by covertly embedding itself within a trusted software installer. This malicious campaign is a sophisticated blend of traditional malware tactics and cryptocurrency theft, posing a significant challenge for detection and defense.

Integration of Malware and Cryptocurrency Theft

Historically, malware targeting credential theft and those aimed at cryptocurrency theft operated independently. However, in recent years, these cyber threats have converged. Attackers have begun repurposing infrastructure used for stealing credentials to also host phishing pages focused on cryptocurrency, while malware groups increasingly incorporate tools for draining digital wallets.

This fusion of threats results in campaigns that can simultaneously compromise user credentials, maintain remote access, and execute financial theft. EtherRAT exemplifies this shift by integrating traditional and blockchain-based attack vectors into a single threat model.

Trojanized Installers Target IT Professionals

EtherRAT’s latest delivery method involves embedding itself within a compromised version of Tftpd64, a popular TFTP server tool for Windows. This altered installer was distributed through a fake GitHub repository masquerading as the legitimate project, offering downloads labeled as “Tftpd64 v4.74.”

The campaign specifically targets IT administrators and network professionals who frequently use Tftpd64 for system management, exploiting their trust in the tool to bypass security measures. This approach allows the malware to integrate quietly into systems, utilizing trusted tool activity to evade scrutiny.

Advanced Persistence and Detection Evasion Techniques

Upon execution, EtherRAT establishes persistence by creating hidden directories and dropping staged components, including a self-contained Node.js runtime. This approach negates reliance on system-installed interpreters, reducing the likelihood of detection by security software.

The malware sets a Windows Run registry key to ensure execution at startup, invoking node.exe in headless mode to load an obfuscated payload. It executes reconnaissance tasks using PowerShell commands, quietly gathering system information while masking activity from the user.

To further its operations, EtherRAT includes multiple Ethereum RPC endpoints, enabling it to execute blockchain interactions and prepare for potential asset theft. The malware encrypts its components using AES-256-CBC, enhancing its resilience against analysis and detection.

Mitigation Strategies for Organizations

Organizations are advised to authenticate software downloads solely from official developer websites and avoid unofficial GitHub sources. Security teams should scrutinize Windows Run registry keys for unusual entries and ensure endpoint protection systems are configured to detect unauthorized access to Ethereum RPC endpoints.

Any system observed to be running Node.js without an apparent developer context should be considered compromised. Immediate investigation is crucial to mitigate the risk posed by this sophisticated threat.

Stay connected with us for more updates on cybersecurity news by following us on Google News, LinkedIn, and X. Consider setting CSN as your preferred source for timely security updates.

Cyber Security News Tags:Blockchain, Cryptocurrency, Cybersecurity, endpoint protection, EtherRAT, GitHub, IT security, Malware, network security, Node.js, Phishing, security threats, Tftpd64, Trojan, Windows

Post navigation

Previous Post: Google Resolves Critical Security Flaws in Gemini CLI Tools
Next Post: AI-Driven Code Attack Targets Crypto Projects

Related Posts

Halo Security Achieves SOC 2 Type 1 Compliance Halo Security Achieves SOC 2 Type 1 Compliance Cyber Security News
Critical Apple WebKit Flaw Patched on iOS and macOS Critical Apple WebKit Flaw Patched on iOS and macOS Cyber Security News
Multi-Stage Windows Malware Invokes PowerShell Downloader Using Text-based Payloads Using Remote Host Multi-Stage Windows Malware Invokes PowerShell Downloader Using Text-based Payloads Using Remote Host Cyber Security News
Retail Finance Giant SitusAMC Data Breach Exposes Accounting Records and Legal Agreements Retail Finance Giant SitusAMC Data Breach Exposes Accounting Records and Legal Agreements Cyber Security News
See Cyber Threats to Your Industry and Region in Just 2 Seconds See Cyber Threats to Your Industry and Region in Just 2 Seconds Cyber Security News
SecSuite: Comprehensive AI-Driven Security Platform Unveiled SecSuite: Comprehensive AI-Driven Security Platform Unveiled Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI-Powered Phishing Threatens Browser Security
  • Critical Rails Vulnerability Allows File Access via Image Uploads
  • Mac Users Threatened by ClickFix Campaign with Atomic Stealer
  • VMware Security Flaws: Auth Bypass and Code Execution Risks
  • Critical Vulnerability in NVIDIA BlueField DPUs Exposes Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI-Powered Phishing Threatens Browser Security
  • Critical Rails Vulnerability Allows File Access via Image Uploads
  • Mac Users Threatened by ClickFix Campaign with Atomic Stealer
  • VMware Security Flaws: Auth Bypass and Code Execution Risks
  • Critical Vulnerability in NVIDIA BlueField DPUs Exposes Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark