Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » EtherRAT Malware Targets Windows Through Fake Tftpd64 Installer

EtherRAT Malware Targets Windows Through Fake Tftpd64 Installer

Cybercriminals Blend Traditional Malware With Crypto Theft

Kelly Cromley by Kelly Cromley
May 5, 2026
in Ethereum News, Market News, News
Reading Time: 3 mins read
0
Malware

A newly identified malware campaign has raised concerns among cybersecurity experts after attackers began distributing an advanced form of malicious software through a fake Windows utility installer. The threat, known as EtherRAT, reportedly combines conventional malware techniques with cryptocurrency-focused attacks, creating a more dangerous and difficult-to-detect threat for Windows users.

Security researchers from LevelBlue SpiderLabs explained that cybercriminal operations had traditionally remained divided between standard malware activity and cryptocurrency-related fraud. Credential-stealing malware, botnets, and remote-access tools generally operated independently from wallet-draining schemes and fake crypto platforms. However, analysts indicated that the distinction between the two sectors has narrowed significantly over the past two years.

Researchers observed that attackers are increasingly reusing infrastructure originally developed for credential theft to support cryptocurrency phishing operations. At the same time, malware operators have reportedly started integrating digital wallet draining capabilities into broader cybercrime campaigns as an additional source of revenue.

The latest EtherRAT campaign reportedly demonstrates how attackers can simultaneously steal login credentials, maintain unauthorized remote access, and target cryptocurrency wallets within a single coordinated attack.

Fake GitHub Repository Used to Spread Malware

According to analysts, EtherRAT initially emerged as a JavaScript-based Node.js implant that targeted Linux servers through known vulnerabilities. The malware has now evolved into a Windows-focused threat distributed through malicious MSI installers.

In the latest campaign, attackers reportedly embedded EtherRAT into a compromised version of Tftpd64, a widely used TFTP server and administration utility for Windows environments. The malware-laced software was distributed through a fraudulent GitHub repository designed to imitate the legitimate Tftpd64 project page.

The fake repository allegedly offered downloads labeled as Tftpd64 v4.74, making the installer appear authentic and encouraging unsuspecting users to install the malicious package as though it were a legitimate software update.

Cybersecurity researchers warned that the campaign is particularly effective because it targets IT administrators and network professionals who regularly use Tftpd64 for system management and maintenance tasks. Since trusted administrative tools often attract less scrutiny from security systems, attackers may gain easier access to enterprise environments.

Persistence Mechanisms and System Reconnaissance

Investigators reported that the malicious archive contained suspicious files with extensions such as .dat, .cmd, .ini, and .tmp. These files were allegedly stored in user-accessible directories within the local application data folder to blend in with legitimate system activity and avoid detection.

After installation, the malware reportedly establishes persistence through a Windows Run registry key. Researchers indicated that this mechanism forces conhost.exe to launch node.exe in headless mode during every user logon, silently loading an obfuscated .dat file that functions as the primary malware payload.

Following persistence setup, EtherRAT allegedly initiates a concealed reconnaissance process using PowerShell commands configured to run without visible windows or profile loading. Analysts explained that this approach allows the malware to gather intelligence from infected systems without alerting users.

The malware reportedly collects a broad range of system information, including device locale settings, GPU details, antivirus products registered within the Windows Security Center, Active Directory domain membership status, and the system’s MachineGuid identifier.

Researchers also stated that EtherRAT downloads an additional Node.js runtime directly from the official Node.js distribution server through curl commands. The malware subsequently communicates with external domains, including wpuadmin[.]shop, while encrypting payload components using AES-256-CBC encryption with embedded keys and initialization vectors.

Blockchain Integration Raises Security Concerns

Researchers highlighted that EtherRAT represents a significant evolution in cybercrime because it directly connects traditional system compromise methods with blockchain-enabled financial theft operations.

The malware bundle reportedly included multiple Ethereum RPC endpoints associated with Flashbots, Tenderly, LlamaRPC, and DRPC, along with several Ethereum wallet addresses. Analysts suggested that these components could allow attackers to conduct blockchain interactions, establish command-and-control communication channels through blockchain data, or facilitate cryptocurrency asset theft.

Once executed, the trojanized installer reportedly creates a hidden directory within the local application data folder and deploys multiple staged components into the infected system. These components include a fully self-contained Node.js runtime environment.

By carrying its own Node.js runtime and executing processes silently in the background, EtherRAT can reportedly avoid traditional detection methods and make malicious activity significantly harder for security teams to identify.

Cybersecurity experts advised organizations to verify software downloads exclusively through official developer websites and avoid unverified GitHub repositories that cannot be confirmed as authentic sources. Security teams were also encouraged to monitor Windows Run registry keys for suspicious node.exe entries or headless execution flags.

Analysts further recommended configuring endpoint protection systems to identify outbound traffic directed toward Ethereum RPC endpoints from non-browser applications. Researchers added that any system found silently running Node.js outside of a legitimate development environment should be treated as a potential compromise and investigated immediately.

 

Previous Post

UXLINK and FishWar Expand AI-Powered Web3 Gaming

Next Post

Nigeria Becomes Africa’s Leading Solana Developer Hub

Related Posts

Pundi X

Pundi X and Units Network Advance AI-Powered Web3 Infrastructure

by Kelly Cromley
May 14, 2026
0

Pundi X has entered a strategic partnership with Units Network to strengthen the connection between artificial intelligence and decentralized blockchain...

algorand

Algorand Launches AlgoKit Utils Beta for Developers

by Kelly Cromley
May 14, 2026
0

Algorand has introduced the beta version of AlgoKit Utils, a major enhancement to its developer toolkit designed for both TypeScript...

Société Générale

Societe Generale Expands Stablecoin Strategy on Canton

by Kelly Cromley
May 14, 2026
0

Societe Generale has expanded its blockchain-based financial infrastructure through the deployment of its EURCV and USDCV stablecoins on the Canton...

Kukkiwon (World Taekwondo Headquarters)

Kukkiwon Launches Blockchain-Based Taekwondo Digital IDs

by Kelly Cromley
May 14, 2026
0

Kukkiwon has officially launched a blockchain-powered digital certification system aimed at modernizing Taekwondo qualification management and improving administrative efficiency. The...

arkham

Arkham Tracks Iran-Linked Tron Wallets Holding $344M

by Kelly Cromley
May 14, 2026
0

Arkham has publicly identified and mapped two Tron blockchain wallets connected to the Central Bank of Iran, offering a detailed...

etherlink

Etherlink Expands Analytics Access Through Dune Integration

by Kelly Cromley
May 14, 2026
0

Etherlink, the EVM-compatible Layer 2 network built on Tezos Smart Rollup technology, has become available on Dune, allowing developers, researchers,...

Next Post
Nigeria

Nigeria Becomes Africa’s Leading Solana Developer Hub

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • SmarTrust Brings Blockchain-Powered Escrow to Freelancers

    by Kelly Cromley
    May 1, 2025
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • Blockchain Based Sports Platform SportsMint Unveiled

    by Kelly Cromley
    Apr 30, 2024

Recent News

Pundi X
Market News

Pundi X and Units Network Advance AI-Powered Web3 Infrastructure

by Kelly Cromley
May 14, 2026
algorand
Market News

Algorand Launches AlgoKit Utils Beta for Developers

by Kelly Cromley
May 14, 2026
Société Générale
Market News

Societe Generale Expands Stablecoin Strategy on Canton

by Kelly Cromley
May 14, 2026
Kukkiwon (World Taekwondo Headquarters)
Market News

Kukkiwon Launches Blockchain-Based Taekwondo Digital IDs

by Kelly Cromley
May 14, 2026
arkham
Market News

Arkham Tracks Iran-Linked Tron Wallets Holding $344M

by Kelly Cromley
May 14, 2026

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
  • XRP
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.