Categories: Cyber Security News

Hackers Weaponize SEO and Fake GitHub Repos In EtherRAT Admin Assault

Atos TRC uncovered a March 2026 EtherRAT campaign that uses SEO poisoning, fake GitHub facades, and Ethereum-based C2 to target enterprise admins and other high-privilege IT users.

The operation is built for resilience: a clean-looking “storefront” repository lures victims first, then redirects them to a second repository that delivers the malicious MSI payload.

Weaponize SEO and Fake GitHub Repos

The attack starts with search poisoning across Bing, Yahoo, DuckDuckGo, and Yandex so that niche admin-tool queries push malicious GitHub results near the top.

The bait is highly targeted, because the fake downloads imitate tools such as PsExec, AzCopy, Sysmon, LAPS, Kusto Explorer, ProcDump, and other utilities commonly used by administrators and security teams.

That focus matters because users who need these tools are more likely to have elevated access, which makes an infection much more valuable to the attacker.

Once the MSI is run, it drops a multi-stage payload that begins with an obfuscated .cmd file and then loads additional stages through Node.js.

Bing search for “kusto explorer” (Source: atos)

Atos described the latest variant as a JavaScript-based RAT that uses layered AES-256-CBC encryption, in-memory execution, and a persistence mechanism through the Windows Run key.

The malware also downloads Node.js at runtime rather than bundling it, which keeps the installer smaller and helps it blend in with normal software activity.

First GitHub repo – used only as a facade (Source: atos)

Blockchain C2

The most unusual part of the campaign is the command-and-control design. Instead of connecting to a fixed domain, the malware queries public Ethereum RPC endpoints to retrieve a live server address from a smart contract. A

tos said the malware checks multiple RPC services in parallel and uses the majority result, which makes the lookup more reliable and harder to disrupt.

Link to second GitHub repo that serves malware to the user (Source: atos)

This approach gives the operators a flexible control plane. They can update the stored address with a blockchain transaction, and infected systems will pick up the new C2 location automatically during the next lookup cycle.

Atos said this removes the need for traditional DNS changes or server redeployment, which weakens common takedown methods.

The RAT then polls its server in a way that resembles ordinary web traffic, using random-looking paths and file extensions to disguise beaconing.

It can receive JavaScript commands, execute them directly inside the Node.js process, and carry out file-system access, OS commands, and data theft without dropping a classic executable.

Atos said the campaign remains active and has continued to mature technically since the first observations.

Cyber defenders should treat this as a targeted enterprise access operation, not a spray-and-pray commodity malware wave.

The combination of SEO poisoning, trusted-platform abuse, and blockchain-based resilience makes it especially difficult to disrupt with routine blocklists alone.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

The post Hackers Weaponize SEO and Fake GitHub Repos In EtherRAT Admin Assault appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

X-Factor Returns in Exclusive X-Men ’97: Season Two Comic Preview

While we're still waiting for confirmation of a release date for the second season of…

32 minutes ago

Subnautica 2 Release Date Announcement Forces Outbound Dev to Bring Its Game Launch Forward

With Subnautica 2 finally getting its May 14 early access release date, it seems Steam's…

32 minutes ago

Star Wars: Galactic Racer – Here’s What Comes in Each Edition

Star Wars: Galactic Racer is set to release for PS5, Xbox Series X|S, and PC…

34 minutes ago

Fake AI ‘Leak’ Trailers Are Filling the Avengers: Doomsday Void — and Misleading Fans

As the wait goes on for Marvel to release the Avengers: Doomsday trailer recently shown…

34 minutes ago

The Best Disney+ Deals and Bundles for May 2026

Considering what it offers, Disney+ is one of the best streaming services on the block.…

36 minutes ago

Amherst council rejects CPA funding for Jones Library woodwork restoration

AMHERST — Restoration of historic wood panels will be completed as part of the $46.1…

43 minutes ago

This website uses cookies.