TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Infosecurity Magazine

EtherRAT Techniques Bypass Security Via Ethereum Smart Contracts

2026-03-26 · Read original ↗

ATT&CK techniques detected

3 predictions
T1204.002Malicious File
89%
“etherrat techniques bypass security via ethereum smart contracts a new etherrat malware campaign using ethereum smart contracts to hide command - and - control ( c2 ) infrastructure has been identified by researchers. according to a new advisory published by esentire on march 25,…”
T1071.001Web Protocols
79%
“##ing security restrictions. the infection chain involved multiple stages, including encrypted payloads and obfuscated scripts that ultimately deployed etherrat and established persistence through windows registry keys. once installed, etherrat retrieved c2 addresses from ethereu…”
T1219Remote Access Tools
44%
“etherrat techniques bypass security via ethereum smart contracts a new etherrat malware campaign using ethereum smart contracts to hide command - and - control ( c2 ) infrastructure has been identified by researchers. according to a new advisory published by esentire on march 25,…”

Summary

EtherRAT hides C2 in Ethereum smart contracts via EtherHiding, steals wallets and credentials