Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2

86881b8e9d197ac2f734792de48d5dfaebe7cafb6e35d49c5dd7fe6eb697230e

TLP:CLEAR
Active

SHA-256 Hash

Description

An exposed open directory at a staging server revealed an active intrusion by operators linked to The Gentlemen ransomware group. The operation involved establishing persistent access through privileged account creation, credential theft via LSASS dumping, and lateral movement across a Windows domain. Attackers deployed multiple implants including EtherRAT, which retrieves command-and-control domains from an Ethereum smart contract, alongside Sliver and custom Go reverse shells. Lateral movement was achieved through remote scheduled tasks distributing MSI payloads, while security products were disabled and reverse tunnels established for persistent access. The infrastructure and tactics align with previously documented The Gentlemen campaigns, including a ClickFix operation deploying EtherRAT.

Sightings (0)

No sightings recorded yet

Details

Name / Label
The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2
Pattern Type
STIX
Confidence
75%
Valid From
Aug 5, 2026 10:01
Total Sightings
0
Added
Aug 5, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 86881b8e9d197ac2f734792de48d5dfaebe7cafb6e35d49c5dd7fe6eb697230e

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.