logo

Remote Scheduled Tasks Spread EtherRAT Across Compromised Windows Domain

ID: a301d720-6399-593e-984e-0fd62a4827b0

STIX ID: report--a301d720-6399-593e-984e-0fd62a4827b0

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-08-05

Date Updated: 2026-08-05

Author: Tushar Subhra Dutta

...
...

A Hunt.io analysis attributes a Windows domain intrusion to a Gentlemen ransomware affiliate that deployed EtherRAT via remote scheduled tasks and MSI installers; the RAT uses blockchain-based C2 resolution, steals credentials and Active Directory data, and the report includes detailed TTPs, IoCs (IPs, domains, filenames, hashes, Ethereum contract), and remediation/detection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.