Remote Scheduled Tasks Spread EtherRAT Across Compromised Windows Domain
ID: a301d720-6399-593e-984e-0fd62a4827b0
STIX ID: report--a301d720-6399-593e-984e-0fd62a4827b0
Feed Name: cybersecurityNews.com
Threat Score
A Hunt.io analysis attributes a Windows domain intrusion to a Gentlemen ransomware affiliate that deployed EtherRAT via remote scheduled tasks and MSI installers; the RAT uses blockchain-based C2 resolution, steals credentials and Active Directory data, and the report includes detailed TTPs, IoCs (IPs, domains, filenames, hashes, Ethereum contract), and remediation/detection recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
