Per Sysdig, North Korean hackers are now exploiting React2Shell to drop EtherRAT, a remote access trojan that uses Ethereum smart contracts as C2
EtherRAT: DPRK uses novel Ethereum implant in React2Shell attacks | Sysdig
A novel Ethereum-powered backdoor, EtherRAT, is being deployed through the React2Shell vulnerability (CVE-2025-55182). With multi-layer persistence, blockchain C2, and self-updating payloads, this malware poses a significant threat. See Sysdig’s full analysis and recommended steps.
(www.sysdig.com)