Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2

7567994310a9576b1f98dc672ecfa038f1d65084315f59e3883f9b6f24000073

TLP:CLEAR
Active

SHA-256 Hash

Description

An exposed open directory at a staging server revealed an active intrusion by operators linked to The Gentlemen ransomware group. The operation involved establishing persistent access through privileged account creation, credential theft via LSASS dumping, and lateral movement across a Windows domain. Attackers deployed multiple implants including EtherRAT, which retrieves command-and-control domains from an Ethereum smart contract, alongside Sliver and custom Go reverse shells. Lateral movement was achieved through remote scheduled tasks distributing MSI payloads, while security products were disabled and reverse tunnels established for persistent access. The infrastructure and tactics align with previously documented The Gentlemen campaigns, including a ClickFix operation deploying EtherRAT.

Sightings (0)

No sightings recorded yet

Details

Name / Label
The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2
Pattern Type
STIX
Confidence
75%
Valid From
Aug 5, 2026 10:01
Total Sightings
0
Added
Aug 5, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 7567994310a9576b1f98dc672ecfa038f1d65084315f59e3883f9b6f24000073

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.