The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum-Based C2

Summary
Hunt.io researchers analyzed files from an exposed directory, detailing a Windows intrusion attributed to The Gentlemen. The toolkit used EtherRAT, which retrieves rotating C2 domains from an Ethereum smart contract, alongside other tools for persistence and access.
Key points
- The exposed directory at 193.233.202[.]17 contained 82 files totaling 145 MB, including scripts, scheduled-task configurations, and an EtherRAT installer.
- Deployment scripts used remote scheduled tasks, administrative shares, certutil.exe, and msiexec.exe to install EtherRAT across Windows hosts.
- EtherRAT retrieves its changing C2 domains from an Ethereum smart contract; researchers reconstructed five historical domains from blockchain records.
- C2 responses longer than ten characters are executed as JavaScript in Node.js, enabling operators to run arbitrary code without replacing the implant.
- The toolkit included methods for creating privileged accounts, dumping credentials and registry hives, disabling ESET services, and establishing persistence.
- Sliver, custom Go reverse shells, Chisel, and Ligolo-ng provided additional command channels and tunneling; researchers assessed the activity as linked to The Gentlemen.
- The malware's X-Bot-Server HTTP header is a potential detection point.
Article Details
- Attack Vectors
- Remote scheduled tasks downloaded and silently installed an EtherRAT MSI across Windows hosts using certutil.exe and msiexec.exe; deployment scripts also used administrative shares and, as a fallback, remote WMI execution.
- A SYSTEM-context scheduled task downloaded and ran task_39.ps1, which created a privileged local account, attempted domain privilege changes, disabled ESET services, exported credential-bearing registry hives, and staged tunneling and reverse-shell components.
- EtherRAT established Run-key persistence and used an Ethereum smart contract to resolve rotating C2 domains. It executed JavaScript received from C2 through Node.js.
- The operator maintained additional command channels through Sliver shellcode, Go reverse shells, and Chisel tunneling.
- Defensive Notes
- The article identifies EtherRAT's custom X-Bot-Server HTTP header as a detection point.
- Ethereum smart-contract updates provide a permanent record from which defenders can reconstruct this sample's historical C2 domains.
- Relevant host artifacts include the MicrosoftSltt installation directory, the WindowsHost Run value, EtherRAT's log and bot-ID files, and the listed remote scheduled-task names.
- The article reports EtherRAT checking the contract approximately every five minutes and describes C2 polling with randomized static-file-like URL paths.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | itemrange[.]com | Historical C2 domain returned by the EtherRAT Ethereum contract. |
| DOMAIN | publisherresolution[.]com | Historical C2 domain returned by the EtherRAT Ethereum contract. |
| DOMAIN | resumeacceptable[.]com | Historical C2 domain returned by the EtherRAT Ethereum contract. |
| DOMAIN | simultaneouslypower[.]com | Historical C2 domain returned by the EtherRAT Ethereum contract. |
| DOMAIN | wiselystarting[.]com | Historical C2 domain returned by the EtherRAT Ethereum contract. |
| IPV4 | 146[.]103[.]127[.]44 | Secondary controller embedded in Go reverse shells. |
| IPV4 | 185[.]117[.]72[.]215 | Historical resolution of EtherRAT C2 domain resumeacceptable[.]com. |
| IPV4 | 185[.]45[.]193[.]151 | Historical resolution of EtherRAT C2 domain publisherresolution[.]com. |
| IPV4 | 193[.]233[.]202[.]17 | Primary staging, C2, Sliver, tunneling, and registry-hive exfiltration server. |
| IPV4 | 38[.]110[.]228[.]125 | Historical resolution of EtherRAT C2 domain itemrange[.]com. |
| IPV4 | 38[.]110[.]228[.]33 | Exposed directory containing artifacts assessed as linked to a The Gentlemen victim. |
| IPV4 | 38[.]110[.]228[.]43 | Historical resolution of EtherRAT C2 domain wiselystarting[.]com. |
| IPV4 | 50[.]114[.]167[.]112 | Historical resolution of EtherRAT C2 domain simultaneouslypower[.]com. |
| IPV4 | 77[.]110[.]122[.]137 | Case-observed The Gentlemen infrastructure with an exposed directory containing Linux-intrusion artifacts. |
| IPV4 | 77[.]110[.]122[.]58 | Staging server associated with a related EtherRAT MSI and Sliver C2. |
| IPV4 | 77[.]110[.]126[.]46 | Secondary controller embedded in Go reverse shells. |
| SHA256 | 73955566338adffb423c3b7608792963080da780e8b7b2c2cd6b6b0cef6f217f | XOR-encrypted EtherRAT backdoor jlfYWzAkN99jpGu.xml. |
| SHA256 | 7567994310a9576b1f98dc672ecfa038f1d65084315f59e3883f9b6f24000073 | EtherRAT decoder and Run-key persistence component YUGKag9mvNKWylo.bin. |
| SHA256 | 756c2096f54c5497110c9d854625c3ed592873e566d532077cd7adb4d10d4add | Multi-controller Go reverse shell ws_3srv.exe. |
| SHA256 | 86881b8e9d197ac2f734792de48d5dfaebe7cafb6e35d49c5dd7fe6eb697230e | Decoded Node.js EtherRAT payload BDQbS2lZ6u.bak. |
| SHA256 | bd61c2880920bbfb86c12df439dd1ca0258a10e532433698fd029aef2a5b33f2 | Standalone Garble-obfuscated Sliver implant svchost_update.exe. |
| SHA256 | c7a80576fbd25057435652788591d13998da272edf627fc29d296684cefc50e5 | Embedded Sliver implant VOCATIONAL_GORILLA extracted from the shellcode. |
| SHA256 | ee6807a8abfabced22ee026e178a28da64d13cc3408e224394ff6e5782fb9e1d | EtherRAT installer cons_c1.0.1.msi deployed by remote scheduled tasks. |
| SHA256 | f4c87a1df04274b7497cbf9a4619b946c915cf5210b6e2eaa2fee1629f4ff196 | Identical multi-controller Go reverse shells update.exe and ws_stable.exe. |
| SHA256 | f609621698eaad8c4683750fe8bd0e242349be3eea408da593151ff877ed8ab6 | Malicious task_39.ps1 script used for account creation, defense impairment, credential theft, tunneling, and reverse shells. |
| SHA256 | f659681525debda69fe0865b2b27a42f684b1fda66aa7398e80b84cc765c73c7 | Node.js bootstrapper jEdb5ROX.cmd installed by the EtherRAT MSI. |
| SHA256 | fb94688ed37dfcb985a8a4d720230e5150956e1788d579b0a54b53a153fd2f2e | SGN/Donut-packaged Sliver beacon shellcode slv_beacon_sc.bin. |
| URL | hxxp[:]//193[.]233[.]202[.]17:42718/task_39[.]ps1 | Staging URL from which a scheduled task downloaded the malicious PowerShell script. |
| URL | hxxp[:]//193[.]233[.]202[.]17:8088/slv_beacon_sc[.]bin | URL used by inject_sliver.ps1 to download Sliver beacon shellcode. |
| URL | hxxps[:]//193[.]233[.]202[.]17/ | C2 endpoint in the recovered Sliver implant configuration. |
| URL | hxxps[:]//itemrange[.]com/ | Historical EtherRAT C2 URL returned by the Ethereum contract. |
| URL | hxxps[:]//publisherresolution[.]com/ | Historical EtherRAT C2 URL returned by the Ethereum contract. |
| URL | hxxps[:]//resumeacceptable[.]com/ | Historical EtherRAT C2 URL returned by the Ethereum contract. |
| URL | hxxps[:]//simultaneouslypower[.]com/ | Historical EtherRAT C2 URL returned by the Ethereum contract. |
| URL | hxxps[:]//wiselystarting[.]com/ | Historical EtherRAT C2 URL returned by the Ethereum contract. |
MITRE ATT&CK
T1003.002 · Security Account Managertask_39.ps1 exports the SAM, SYSTEM, and SECURITY registry hives and uploads them to actor infrastructure.T1021.002 · SMB/Windows Admin SharesDeployment scripts copy payloads to remote administrative shares.T1047 · Windows Management Instrumentationdeploy.cmd uses remote wmic process call create as a fallback to launch certutil.exe.T1053.005 · Scheduled TaskRemote scheduled tasks, including WinSvcUpdate2, execute deployment payloads.T1059.001 · PowerShellHidden PowerShell download cradles execute task_39.ps1, and PowerShell loads Sliver shellcode.T1059.003 · Windows Command ShellDeployment batch files and custom Go backdoors execute commands through cmd.exe.T1059.007 · JavaScriptNode.js executes the decoded EtherRAT JavaScript backdoor and evaluates JavaScript received from C2.T1071.001 · Web ProtocolsEtherRAT polls C2 over HTTP(S); payload staging, registry-hive uploads, and Sliver C2 also use web protocols.T1102.001 · Dead Drop ResolverEtherRAT queries an Ethereum smart contract through public RPC services to retrieve its current C2 domain.T1105 · Ingress Tool Transfercertutil.exe, PowerShell WebClient, and curl.exe retrieve scripts, installers, shellcode, and other payloads.T1112 · Modify RegistryIntrusion scripts modify RDP and UAC-related registry settings; EtherRAT creates a Run value.T1136.001 · Local Accounttask_39.ps1 and other recovered payloads create the local account support2.T1136.002 · Domain Accountadduser.ps1 creates the svcadm Active Directory account; task_39.ps1 also attempts to create support2 in the domain.T1218.007 · Msiexecmsiexec.exe silently installs the EtherRAT MSI on remote hosts.T1547.001 · Registry Run Keys / Startup FolderEtherRAT creates the WindowsHost Run value to launch its Node.js payload through headless conhost.exe.T1562.001 · Disable or Modify Toolstask_39.ps1 stops and disables ESET services, while fix_uac.bat disables UAC.T1572 · Protocol TunnelingChisel is configured to establish reverse SOCKS tunnels to 193.233.202[.]17.T1620 · Reflective Code Loadinginject_sliver.ps1 loads downloaded Sliver shellcode into executable memory and starts it with CreateThread.
CVE
Threat Actors
Malware
EtherRATmovement ran through remote scheduled tasks that downloaded and executed MSI payloads. Those installed EtherRAT, a persistent implant that pulls its C2 domains from an Ethereum smart contract instead of hardcodingSliverimplant that pulls its C2 domains from an Ethereum smart contract instead of hardcoding them, while Sliver and Go reverse-shell binaries gave the operator additional command channels.
Vendors
Products
Ethereumexecuted MSI payloads. Those installed EtherRAT, a persistent implant that pulls its C2 domains from an Ethereum smart contract instead of hardcoding them, while Sliver and Go reverse-shell binaries gave the operatorMicrosoft Windowsat 193.233.202[.]17 caught an operator tied to The Gentlemen ransomware mid-intrusion, setting up a Windows domain for persistent access, credential theft, and lateral movement. The files left behind trace theNode.jsAny C2 response over ten characters is run as JavaScript inside a Node.js runtime, giving the operator arbitrary code execution and letting them extend capabilities without replacing the implant.
Tools
AttackCapturethe Hunt.io platform we can see this IP has been is linked to Sliver malware on port 31337, with AttackCapture entries exposing the threat actors infrastructure:ChiselC2 layers, the toolkit covered credential theft (Mimikatz, registry-hive and LSASS dumping), tunneling (Chisel, Ligolo-ng), and Potato-family privilege escalation, showing an operator equipped for the full path toGodPotatoSeveral privilege-escalation scripts were observed. gp_reflect.ps1 loads a GodPotato payload in memory and changes LocalAccountTokenFilterPolicy. fix_uac.bat disables UAC and changes the same policy. ms16032.ps1Hunt.ioMay 21st write-up on The Gentlemen's defense evasion TTPs. Both IPs showed up as open directories on the Hunt.io platform through the IOC Hunter feature. On June 16th, Huntress also published a ClickFix campaign thatIOC Hunterdefense evasion TTPs. Both IPs showed up as open directories on the Hunt.io platform through the IOC Hunter feature. On June 16th, Huntress also published a ClickFix campaign that deployed EtherRAT. ThatJuicyPotatojp.exe - JuicyPotato x64 exploitLigolo-ngthe toolkit covered credential theft (Mimikatz, registry-hive and LSASS dumping), tunneling (Chisel, Ligolo-ng), and Potato-family privilege escalation, showing an operator equipped for the full path to domain-wideMimikatzBeyond the C2 layers, the toolkit covered credential theft (Mimikatz, registry-hive and LSASS dumping), tunneling (Chisel, Ligolo-ng), and Potato-family privilege escalation, showing an operator equipped for the fullPrintSpooferps64.exe - PrintSpoofer x64 exploit