CyberSecurityBoardThreat Intel · CVEs · Products
Malware

DeviceManager: Python-Based RAT Using EtherHiding

August 4, 2026

DeviceManager is a modular Python-based remote access trojan distributed via DOUBLECUP. It uses EtherHiding to resolve C2 servers via Ethereum/Polygon smart contracts and communicates over HTTP or DNS tunneling. It avoids CIS language locales and can execute PowerShell and Python scripts.