Gentlemen Affiliate Deploys EtherRAT via Ethereum Smart Contract C2
A Gentlemen ransomware affiliate has been linked to an exposure of EtherRAT via Ethereum smart contract C2. An exposed directory on IP address 193.233.202[.]17 revealed a detailed intrusion toolkit, including files for long-term access to Windows networks and credential stealing.
The recovered files showed an operator preparing to deploy several command-and-control (C2) channels, including EtherRAT, which does not store a fixed C2 domain inside the malware. Instead, it queries an Ethereum smart contract through public RPC services to retrieve its active C2 address.
Researchers reconstructed five historical EtherRAT domains, including publisherresolution[.]com and resumeacceptable[.]com. The affiliate used living-off-the-land binaries to avoid relying on custom malware and implemented a repeatable method to spread access across a Windows domain.