Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

More sophisticated EtherRAT malware variant delivered via trojanized installer

Threat actors are distributing a more sophisticated variant of EtherRAT malware via a trojanized installer of the Tftpd64 Windows TFTP tool, downloaded from a spoofed GitHub repository. The malware establishes persistence in the local AppData folder, deploys a Node.js runtime to evade detection, and conducts system reconnaissance before targeting Ethereum wallets and RPC endpoints. Organizations should download software only from official sources and monitor Windows Run registry keys for suspicious entries.
Read Full Article →

Malware More sophisticated EtherRAT malware variant delivered via trojanized installer May 1, 2026 Share By SC Staff (Adobe Stock) Threat actors have leveraged a malicious copy of the popular Windows TFTP server and admin tool, Tftpd64, to compromise IT administrators and network professionals with an updated iteration of the EtherRAT malware as part of a new hybrid attack campaign that combines system compromise with cryptocurrency theft, according to Cyber Security News . Executing the illicit Tftpd64 installer file downloaded from a spoofed GitHub repository enables EtherRAT to establish a concealed directory within the local app data folder while deploying a self-contained Node.js runtime and other staged components to evade security tools, a report from LevelBlue SpiderLabs researchers. Once persistence is ensured, EtherRAT proceeds with covert system reconnaissance, obtaining Active Directory domain membership, system locale, and other details, before downloading another Node.js runtime and targeting several Ethereum RPC endpoints and Ethereum wallet addresses. Organizations have been urged to not only download software from official developer websites but also observe suspicious entries in Windows Run registry keys to combat the threat. SC Staff Related Malware New software supply chain attack uses sleeper packages for credential theft and CI tampering SC Staff May 1, 2026 The campaign, attributed to the GitHub account "BufferZoneCorp," involved malicious Ruby gems and Go modules disguised as legitimate libraries. Malware Clandestine Deep#Door stealer facilitates long-term data compromise SC Staff May 1, 2026 Infosecurity Magazine reports that Windows systems are being stealthily targeted for protracted surveillance and credential exfiltration with the new Python-based Deep#Door backdoor framework. Malware Celebrity data leak exposes private photos and messages due to stalkerware SC Staff May 1, 2026 Cybersecurity researcher Jeremiah Fowler discovered the data, which included intimate chat logs from apps like WhatsApp, Facebook, TikTok, and Instagram. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Adware You can skip this ad in 5 seconds

Share this article