logo

The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2

ID: 86c112d6-a0ed-5cf8-a68b-6bd8bd430a0a

STIX ID: report--86c112d6-a0ed-5cf8-a68b-6bd8bd430a0a

Feed Name: Hunt.io Blog

Threat Score
80/100

Date Published: 2026-08-05

Date Updated: 2026-08-10

...
...

This report details an exposed open directory that revealed a coordinated intrusion by an operator tied to The Gentlemen ransomware: a complete Windows operator toolkit was recovered showing account creation, LSASS and registry-hive dumping, scheduled-task-based lateral movement installing EtherRAT (which resolves C2 via an Ethereum smart contract), Sliver and Go reverse shells, tunneling tools (Chisel, Ligolo-ng), and multiple persistence mechanisms; the report includes IoCs (IPs, domains, file hashes), MITRE ATT&CK mappings, and links infrastructure clustering to the threat actor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.