Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2

bd61c2880920bbfb86c12df439dd1ca0258a10e532433698fd029aef2a5b33f2

TLP:CLEAR
Active

SHA-256 Hash

Description

An exposed open directory at a staging server revealed an active intrusion by operators linked to The Gentlemen ransomware group. The operation involved establishing persistent access through privileged account creation, credential theft via LSASS dumping, and lateral movement across a Windows domain. Attackers deployed multiple implants including EtherRAT, which retrieves command-and-control domains from an Ethereum smart contract, alongside Sliver and custom Go reverse shells. Lateral movement was achieved through remote scheduled tasks distributing MSI payloads, while security products were disabled and reverse tunnels established for persistent access. The infrastructure and tactics align with previously documented The Gentlemen campaigns, including a ClickFix operation deploying EtherRAT.

Sightings (0)

No sightings recorded yet

Details

Name / Label
The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2
Pattern Type
STIX
Confidence
75%
Valid From
Aug 5, 2026 10:01
Total Sightings
0
Added
Aug 5, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of bd61c2880920bbfb86c12df439dd1ca0258a10e532433698fd029aef2a5b33f2

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.