Threat actors with connections to North Korea are probably the most current to use the recently revealed major security React2Shell vulnerability in React Server Components (RSC) to distribute an unreported remote access trojan known as EtherRAT.
In a research released on Monday, Sysdig stated that EtherRAT uses five separate Linux persistence techniques, downloads its own Node.js runtime from nodejs.org, and uses Ethereum smart contracts for command-and-control (C2) resolution.
According to the cloud security company, there is a substantial overlap between the activity and a long-running campaign known as Contagious Interview, which has been using the EtherHiding approach to spread malware since February 2025.
The term “Contagious Interview” refers to a set of attacks that target Web3 and blockchain engineers, among others, using fictitious employment interviews read more about North Korea-linked Actors Exploit React2Shell to Deploy New EtherRAT Malware.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
