Skip to main content

The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2

0
Medium
Published: 08/05/2026 (08/05/2026, 08:26:37 UTC)
Source: Reddit NetSec

Description

An exposed open directory at a staging server revealed an active intrusion by operators linked to The Gentlemen ransomware group. The operation involved establishing persistent access through privileged account creation, credential theft via LSASS dumping, and lateral movement across a Windows domain. Attackers deployed multiple implants including EtherRAT, which retrieves command-and-control domains from an Ethereum smart contract, alongside Sliver and custom Go reverse shells. Lateral movement was achieved through remote scheduled tasks distributing MSI payloads, while security products were disabled and reverse tunnels established for persistent access. The infrastructure and tactics align with previously documented The Gentlemen campaigns, including a ClickFix operation deploying EtherRAT.

Reddit Discussion

r/netsec·posted by u/Straight-Practice-99
00

Defensive-leaning breakdown of a The Gentlemen intrusion recovered from an exposed open directory. Detection surface worth noting:

  • X-Bot-Server HTTP header on EtherRAT polling traffic
  • Scheduled task names: WinSvcUpdate2, WindowsUpdSvc31, WindowsUpdateSvc, SysUpdate
  • LOLBAS chain: certutil.exe fetches the MSI, msiexec.exe installs silently
  • Run-key WindowsHost under HKCU launching Node.js through headless conhost.exe
  • ESET service tampering via sc.exe across eight named services
  • EtherRAT install path %LOCALAPPDATA%\MicrosoftSltt and log at %APPDATA%\svchost.log

Full detail, MITRE mapping and IOCs: https://hunt.io/blog/the-gentlemen-etherrat-ethereum-smart-contract-c2 .

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/04/2026, 18:26:20 UTC

Technical Analysis

EtherRAT is a remote access trojan deployed by The Gentlemen affiliate that leverages an Ethereum smart contract for its command and control infrastructure. The malware targets Windows environments and uses various persistence mechanisms including scheduled tasks named WinSvcUpdate2, WindowsUpdSvc31, WindowsUpdateSvc, and SysUpdate. It employs LOLBAS techniques such as using certutil.exe to fetch MSI installers and msiexec.exe for silent installation. The malware also manipulates Windows services via sc.exe and installs itself under %LOCALAPPDATA%\MicrosoftSltt with logs stored in %APPDATA%\svchost.log. The C2 communication is identifiable by an X-Bot-Server HTTP header in the polling traffic. The use of blockchain-based C2 is notable for its resilience and stealth. The detailed analysis and IOCs are documented in the referenced hunt.io blog post.

Potential Impact

The deployment of EtherRAT enables attackers to maintain persistent remote access on compromised Windows systems. The use of Ethereum smart contract-based C2 infrastructure complicates detection and takedown efforts. The malware's use of legitimate Windows tools and scheduled tasks aids in evasion and persistence. This can lead to unauthorized data access, lateral movement, and potential further compromise within affected networks.

Defensive Guidance

No official patch or remediation is indicated in the available information. Defenders should refer to the detailed indicators of compromise and MITRE ATT&CK mappings provided in the linked vendor blog for detection and response. Monitoring for the specified scheduled task names, unusual use of certutil.exe and msiexec.exe, presence of the X-Bot-Server HTTP header in network traffic, and service tampering activities can aid in identifying infections. Incident response should focus on removing the malware and associated persistence mechanisms. Since this is a malware campaign rather than a software vulnerability, patching is not applicable.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
netsec
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true}
Has External Source
true
Trusted Domain
false

Indicators of Compromise

Ip

ValueDescriptionCopy
ip193.233.202.17
ip185.45.193.151
ip38.110.228.43
ip77.110.122.137
ip77.110.126.46
ip77.110.122.58
ip146.103.127.44
ip185.117.72.215
ip38.110.228.125
ip38.110.228.33
ip50.114.167.112

Domain

ValueDescriptionCopy
domainresumeacceptable.com
domainpublisherresolution.com
domainsimultaneouslypower.com
domainwiselystarting.com
domainitemrange.com

Hash

ValueDescriptionCopy
hash4b690f3ce585df982a042917b82642c8
hashbd1eaea733425cd21a51a652c429951d
hash60285f6776cc3ff20872feeee7f2fd0b3b04410d
hash9dd99bc68e60132f32fc33617deb9583c8cebb51
hash73955566338adffb423c3b7608792963080da780e8b7b2c2cd6b6b0cef6f217f
hash7567994310a9576b1f98dc672ecfa038f1d65084315f59e3883f9b6f24000073
hash756c2096f54c5497110c9d854625c3ed592873e566d532077cd7adb4d10d4add
hash86881b8e9d197ac2f734792de48d5dfaebe7cafb6e35d49c5dd7fe6eb697230e
hashbd61c2880920bbfb86c12df439dd1ca0258a10e532433698fd029aef2a5b33f2
hashc7a80576fbd25057435652788591d13998da272edf627fc29d296684cefc50e5
hashee6807a8abfabced22ee026e178a28da64d13cc3408e224394ff6e5782fb9e1d
hashf4c87a1df04274b7497cbf9a4619b946c915cf5210b6e2eaa2fee1629f4ff196
hashf609621698eaad8c4683750fe8bd0e242349be3eea408da593151ff877ed8ab6
hashf659681525debda69fe0865b2b27a42f684b1fda66aa7398e80b84cc765c73c7
hashfb94688ed37dfcb985a8a4d720230e5150956e1788d579b0a54b53a153fd2f2e

Url

ValueDescriptionCopy
urlhttp://193.233.202.17:9001

Threat ID: 6a722eb9bf8831d5393dec1a

Added to database: 08/04/2026, 18:26:01 UTC

Last enriched: 08/04/2026, 18:26:20 UTC

Last updated: 09/18/2026, 21:23:00 UTC

Views: 149

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses