Ransomware Hackers Are Hiding Malware Command Servers Inside Ethereum Smart Contracts
ID: 06a36899-7426-59cf-bb48-55234ca895a0
STIX ID: report--06a36899-7426-59cf-bb48-55234ca895a0
Feed Name: GBHackers
This report details an active Gentlemen ransomware affiliate operation that deploys a Node.js backdoor (EtherRAT) via MSI and scheduled tasks, uses Ethereum smart contracts to publish rotating C2 domains for resilient, takedown-resistant command-and-control, and leverages Sliver, Go-based reverse shells, and tunneling tools for lateral movement and exfiltration; Hunt.io captured extensive artifacts from exposed open directories tying multiple IPs/ASNs to the campaign and listing detailed IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
