TL;DR

  • ETHERRAT (Windows backdoor): Node.js-based backdoor that uses EtherHiding to retrieve and update its C2 infrastructure through Ethereum smart contracts. Uses ClickFix-style delivery, proxy execution through pcalua.exe and mshta.exe, AES-256-CBC decryption, and HKCU Run key persistence. Beaconing is designed to resemble CDN traffic and the malware can re-obfuscate itself by receiving modified source code from C2.
  • OCRFix (Windows loader/botnet component): Multi-stage malware that uses blockchain-based configuration retrieval and scheduled-task persistence. Stores payloads in ZIP archives, creates CfgHelper and CfgMgr tasks, and maintains a loader → modules chain.
  • SILENTCONNECT (Windows loader): Multi-stage loader that uses VBScript, in-memory PowerShell execution, and PEB masquerading to deploy ScreenConnect. Starts from a lure page, drops FileR.txt, compiles C# payload in memory, bypasses UAC, and installs ScreenConnect as a service.

1) ETHERRAT (Windows)

Sample: ANY.RUN

ETHERRAT is a Node.js-based backdoor that leverages the EtherHiding technique to retrieve and update its command-and-control (C2) infrastructure via Ethereum smart contracts. It uses CDN-like HTTPS beaconing to blend malicious traffic with legitimate services and supports remote command execution, system profiling, and theft of crypto wallets and cloud credentials.

How to detect: Detected by monitoring abnormal file activities and command lines.

Key facts:

  • Delivered via ClickFix technique; abuses pcalua.exe to proxy execution of mshta.exe, which retrieves and runs a malicious HTA script.
  • Multi-stage loader: initial stages decrypt payloads using AES-256-CBC and execute them in memory; persistence is achieved via HKCU Run key.
  • C2 addresses are dynamically fetched from Ethereum through public RPC providers; operators can update them using smart contract functions such as setString to redirect infected hosts.
  • Beaconing mimics CDN traffic: /api/ + random hex + UUID + fake static file extensions such as .png, .jpg, and .css, with query parameters like id, token, and key; communication occurs over HTTPS/TLS 1.3.
  • Self-reobfuscation capability: malware sends its own source code to C2, receives a modified version, overwrites itself, and restarts.
  • SYS_INFO module performs geofencing by exiting on CIS languages and collects detailed host data including IP, CPU, OS, RAM, uptime, MAC, GPU, AV, domain, privileges, and machine ID.

Analytical note:

Detected External sources ANY.RUN Last Submission Sandbox Evasion VT First Submission
2026-04-06 esentire.co 2026-04-06 0 2026-04-06

With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.

TI Lookup: commandLine:"set r=%RANDOM%%RANDOM%%RANDOM%%RANDOM%" OR threatName:"etherrat"

IOCs:

  • SHA256: a27fe395b51d1cca93bf609a97d53013e94e1dd90166fc4483d334f183eb814a
  • SHA256: 6fad8f53a7583b6ee9be41c80b2b564aed8bfdbd6a7e5a63f5e3cf312a43aaa6

MITRE:

Technique ID Technique Name Evidence
T1059.001 Command and Scripting Interpreter: PowerShell Starts POWERSHELL.EXE for commands execution.
T1059.003 Command and Scripting Interpreter: Windows Command Shell Starts CMD.EXE for commands execution.
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder Changes the autorun value in the registry.
T1564.003 Hide Artifacts: Hidden Window Runs PowerShell with an invisible window.
T1082 System Information Discovery Lists computer manufacturer and model.
T1135 Network Share Discovery Starts NET.EXE to display or manage information about active sessions.

2) OCRFix (Windows)

Sample: ANY.RUN

OCRFix is a malware loader and botnet component used in the EtherHiding chain to deliver and execute additional payloads. It is distributed through malicious websites and uses a multi-stage loading flow with configuration retrieval from blockchain infrastructure on Binance Smart Chain. After infection, it deploys modules, establishes persistence through scheduled tasks, and periodically pulls updates or new components. Its main purpose is stealthy delivery of the next stage and remote control of the system.

How to detect: Detected by characteristic artifacts and persistence mechanisms, including C:\ProgramData\app_config\configpackT.zip, C:\Users\admin\AppData\Local\update_data.zip, and scheduled-task creation for CfgHelper and CfgMgr.

Key facts:

  • Uses EtherHiding to obtain configuration through blockchain infrastructure on BSC, which makes C2 blocking harder.
  • Implements a multi-stage loader chain: loader → modules.
  • Stores payloads as ZIP archives in ProgramData and AppData.
  • Persists through Scheduled Tasks with frequent execution intervals of 5 to 30 minutes.
  • Supports component updates and downloads of new modules.
  • Masquerades as legitimate system or service processes.

Analytical note:

Detected External sources ANY.RUN Last Submission Sandbox Evasion VT First Submission
2026-03-23 derp.ca 2026-04-07 61 2026-02-28

With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.

TI Lookup: filePath:"\\app_config\\configpackT.zip" OR filePath:"C:\\Users\\admin\\AppData\\Local\\update_data.zip" OR commandLine:"/create /tn *CfgHelper*" OR commandLine:"/create /tn *CfgMgr*"

IOCs:

  • File: C:\ProgramData\app_config\configpackT.zip
  • File: C:\Users\admin\AppData\Local\update_data.zip
  • Scheduled task: CfgHelper
  • Scheduled task: CfgMgr

MITRE:

Technique ID Technique Name Evidence
T1053.005 Scheduled Task Creates tasks CfgHelper and CfgMgr for regular execution.
T1105 Ingress Tool Transfer Downloads additional modules and updates.
T1071.001 Web Protocols Uses internet/blockchain for configuration retrieval.
T1027 Obfuscated/Compressed Files Stores payload in ZIP archives such as configpackT.zip and update_data.zip.
T1547 Boot or Logon Autostart Persists through the task scheduler.
T1036 Masquerading Uses names like CfgHelper and CfgMgr.
T1496 Resource Hijacking May use the system as part of a botnet.

3) SILENTCONNECT (Windows)

Sample: ANY.RUN

SILENTCONNECT is a multi-stage Windows loader that uses VBScript, in-memory PowerShell execution, and PEB masquerading to silently deploy ScreenConnect on victim hosts. The infection chain starts from a lure page with a Cloudflare Turnstile CAPTCHA, downloads a VBScript, retrieves a C# source payload, compiles it in memory, and finally installs ScreenConnect. The campaign also uses trusted hosting and delivery infrastructure such as Google Drive and Cloudflare object storage.

How to detect: Detection based on identifying artifacts such as C:\Windows\Temp\FileR.txt and execution of a command matching HelloWorld -> SayHello(), together with the associated PowerShell/C# download-and-execute chain.

Key facts:

  • The initial stage is a VBScript lure; the script is minimally obfuscated and uses Replace() and Chr() to hide the next stage.
  • The script downloads FileR.txt to C:\Windows\Temp\ and then compiles and runs the C# payload in memory through Add-Type and [HelloWorld]::SayHello().
  • The loader allocates executable memory with NtAllocateVirtualMemory, runs shellcode to recover the PEB, and uses PEB masquerading by rewriting its own module name and path to winhlp32.exe and c:\windows\winhlp32.exe.
  • Before launching the payload, it attempts a UAC bypass through the CMSTPLUA COM interface and adds a Microsoft Defender exclusion for .exe files.
  • The final stage downloads and installs a ScreenConnect MSI with curl.exe and msiexec.exe, and the installed client persists as a Windows service and beacons to the actor-controlled ScreenConnect server over TCP port 8041.
  • The campaign also uses phishing-style lure pages and repeatedly reused paths such as download_invitee.php, which made infrastructure tracking easier.

Analytical note:

Detected External sources ANY.RUN Last Submission Sandbox Evasion
2026-03-31 elastic.co 2026-04-06 18

With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.

TI Lookup: filePath:"C:\\Windows\\Temp\\FileR\\.txt"

IOCs:

  • SHA256: 8bab731ac2f7d015b81c2002f518fff06ea751a34a711907e80e98cf70b557db
  • SHA256: d6c8bdd4e8b6d64f619c0277b26fa68c6117dae36bb9a3707b4d89d4a88e343a
  • SHA256: 225e08c08d3664d6acb586d5966a0c3e7d2e26f8fc399e51401f41759ef9d426
  • SHA256: d4ea4170e3fc909ca0224926bf3a161e25100a432b1740fe20535e7d9b8bfc1c
  • SHA256: b6e5ede61684a2246797a01a6b6aeb8f99603044abb8a23663da0395edf6f20a
  • SHA256: 9151b980b245d1958edf7af62fc772ad1553c7de68cffe535f2f7f3c536895df
  • SHA256: 57b795c477b2939d96dfe59147ad8fd5d7228a2b7330119f04b59eff4d2fc842
  • SHA256: f45f2aa75aff84dd02d903feee56f44a316b72a8e42455f87b0c395df525e827
  • SHA256: 2ed3d6e02b99b433e07cf382b93c4df0356530f16ad26eed380e5bf8bbe8968c
  • SHA256: 7577ae95e892eda34e00304308715c65a197216854a85cecfbfd402a3a8964e0
  • SHA256: 1dfe062f6413a6dece21ac3e993d9b76a472dd1c8f6a01adaa76ba9e9a19487d
  • SHA256: 4259f7efcf96a38f7c74be9187e0be57d54e8d0cd33bf9355d8f42b60555cb4f
  • SHA256: d59b286542d7643f665df44deabf74653b7ba84ea72a5ce61a73c739c85d28ce
  • SHA256: fffecd8d1d35f706cfe49c9c62a0448bd65f41db6c73542c12c6d36deff63a60

MITRE:

Technique ID Technique Name Evidence
T1059.001 Command and Scripting Interpreter: PowerShell The VBScript stage launches PowerShell to download and compile the C# payload in memory.
T1105 Ingress Tool Transfer The loader downloads FileR.txt from Google Drive and later downloads the ScreenConnect MSI.
T1027 Obfuscated Files or Information The VBScript uses Replace() and Chr() for obfuscation, and the C# payload uses constant unfolding.
T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control The loader attempts a UAC bypass via the CMSTPLUA COM interface.
T1562.001 Impair Defenses: Disable or Modify Tools The script adds a Microsoft Defender exclusion for .exe files.
T1219 Remote Access Software The final payload is ScreenConnect, deployed as an RMM tool for remote control.

Conclusion

  • ETHERRAT stands out through its blockchain-backed C2 updates, CDN-like HTTPS beaconing, and the combination of ClickFix delivery and proxy execution through pcalua.exe and mshta.exe.

  • OCRFix is most reliably identified by the paired ZIP artifacts and its scheduled-task persistence, especially the CfgHelper and CfgMgr task names.

  • SILENTCONNECT leaves a strong execution trail through C:\Windows\Temp\FileR.txt, in-memory PowerShell/C# execution, and the final ScreenConnect installation chain.

  • Across all three families, the most effective hunting strategy is to combine file artifacts, command-line patterns, and persistence behavior with the network indicators listed above.