Unmasking the Facade: Stealthy EtherRAT Distribution via Impersonated Administrative Tools on GitHub — Wojciech Bohatyrewicz, Piotr Bienias

Join us at hack.lu 2026 — Info & Registration

Duration: 30 min

Type: Talk

Speakers: Wojciech Bohatyrewicz, Piotr Bienias

Abstract

In early 2026, Atos Threat Research Center (TRC) identified a sophisticated, high-resilience malicious campaign distributing malware EtherRAT. This operation specifically targets high-privilege IT professionals - enterprise administrators, DevOps engineers and security analysts - who hold broad credentials within corporate environments. The attackers leverage a combination of Search Engine Optimization (SEO) poisoning, impersonated administrative tools and a decentralized Command-and-Control (C2) mechanism utilizing the Ethereum blockchain to maintain persistence and bypass traditional security trust models.

Description

With our talk we want to lead audience in holistic manner through all important aspects of the campaign:
Malware Distribution: analysis of the two-stage GitHub repository setup, combined with the use of SEO poisoning to influence search rankings and increase victim exposure.
Administrative Tools Impersonation: examination of how legitimate administrative utilities are mimicked to target and compromise high-privilege IT users.
Malware Logic: technical breakdown of the malicious MSI payloads, covering both the initial execution stages and mechanisms for persistence.
Decentralized C2 Infrastructure: exploration of the use of Ethereum Smart Contracts and public RPC endpoints to dynamically retrieve active Command-and-Control (C2) addresses.

The GitHub “Facade” Methodology and SEO-poisoning
Central to the campaign is a “dual-stage” GitHub infrastructure designed for maximum longevity. Attackers deploy GitHub facades - SEO optimized repositories that impersonate essential enterprise utilities such as PsExec, AzCopy, Sysmon, LAPS, KustoExplorer (and lot more).

The facade repositories do not host malware directly. Instead, they use README files to redirect victims to hidden “payload” repositories hosting malicious MSI installers. This separation allows attackers to rapidly rotate their delivery infrastructure if a payload is flagged, while the primary, search-indexed storefronts remain operational. Atos TRC identified at least 44 distinct facades between December 2025 and April 2026.

Technical Analysis of EtherRAT
The analyzed malware is a multi stage EtherRAT variant delivered via malicious MSI installers impersonating enterprise administrative tools.

  1. Execution starts from an obfuscated SYSTEM level batch dropper, moves to in memory Node.js loaders using layered AES 256 CBC encryption and ends in a persistent JavaScript RAT executed through conhost.exe with Run key persistence.
  2. The RAT implements decentralized C2 resolution by querying an Ethereum smart contract via multiple public RPC endpoints, enabling resilient, dynamically updated C2 without hardcoded infrastructure.
  3. Command execution is achieved via runtime JavaScript evaluation, with continuous self re obfuscation and CDN like beaconing patterns to evade static and network based detection.

Blockchain-based C2 (“EtherHiding” module)
In a departure from traditional RATs, EtherRAT queries public Ethereum RPC endpoints to retrieve live C2 addresses each 5 minutes. It reads these values from a transaction values related to Smart Contract on the blockchain. This “EtherHiding” logic makes the infrastructure virtually immune to traditional blocklisting/takedowns, as attackers can update their C2 server globally by simply updating the Smart Contract transaction value.

View on pretalx