The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum-Based C2

· Original article ↗

Summary

Hunt.io researchers analyzed files from an exposed directory, detailing a Windows intrusion attributed to The Gentlemen. The toolkit used EtherRAT, which retrieves rotating C2 domains from an Ethereum smart contract, alongside other tools for persistence and access.

Key points

  • The exposed directory at 193.233.202[.]17 contained 82 files totaling 145 MB, including scripts, scheduled-task configurations, and an EtherRAT installer.
  • Deployment scripts used remote scheduled tasks, administrative shares, certutil.exe, and msiexec.exe to install EtherRAT across Windows hosts.
  • EtherRAT retrieves its changing C2 domains from an Ethereum smart contract; researchers reconstructed five historical domains from blockchain records.
  • C2 responses longer than ten characters are executed as JavaScript in Node.js, enabling operators to run arbitrary code without replacing the implant.
  • The toolkit included methods for creating privileged accounts, dumping credentials and registry hives, disabling ESET services, and establishing persistence.
  • Sliver, custom Go reverse shells, Chisel, and Ligolo-ng provided additional command channels and tunneling; researchers assessed the activity as linked to The Gentlemen.
  • The malware's X-Bot-Server HTTP header is a potential detection point.

Article Details

Attack Vectors
  • Remote scheduled tasks downloaded and silently installed an EtherRAT MSI across Windows hosts using certutil.exe and msiexec.exe; deployment scripts also used administrative shares and, as a fallback, remote WMI execution.
  • A SYSTEM-context scheduled task downloaded and ran task_39.ps1, which created a privileged local account, attempted domain privilege changes, disabled ESET services, exported credential-bearing registry hives, and staged tunneling and reverse-shell components.
  • EtherRAT established Run-key persistence and used an Ethereum smart contract to resolve rotating C2 domains. It executed JavaScript received from C2 through Node.js.
  • The operator maintained additional command channels through Sliver shellcode, Go reverse shells, and Chisel tunneling.
Defensive Notes
  • The article identifies EtherRAT's custom X-Bot-Server HTTP header as a detection point.
  • Ethereum smart-contract updates provide a permanent record from which defenders can reconstruct this sample's historical C2 domains.
  • Relevant host artifacts include the MicrosoftSltt installation directory, the WindowsHost Run value, EtherRAT's log and bot-ID files, and the listed remote scheduled-task names.
  • The article reports EtherRAT checking the contract approximately every five minutes and describes C2 polling with randomized static-file-like URL paths.

Indicators of compromise

TypeIndicatorContext
DOMAINitemrange[.]comHistorical C2 domain returned by the EtherRAT Ethereum contract.
DOMAINpublisherresolution[.]comHistorical C2 domain returned by the EtherRAT Ethereum contract.
DOMAINresumeacceptable[.]comHistorical C2 domain returned by the EtherRAT Ethereum contract.
DOMAINsimultaneouslypower[.]comHistorical C2 domain returned by the EtherRAT Ethereum contract.
DOMAINwiselystarting[.]comHistorical C2 domain returned by the EtherRAT Ethereum contract.
IPV4146[.]103[.]127[.]44Secondary controller embedded in Go reverse shells.
IPV4185[.]117[.]72[.]215Historical resolution of EtherRAT C2 domain resumeacceptable[.]com.
IPV4185[.]45[.]193[.]151Historical resolution of EtherRAT C2 domain publisherresolution[.]com.
IPV4193[.]233[.]202[.]17Primary staging, C2, Sliver, tunneling, and registry-hive exfiltration server.
IPV438[.]110[.]228[.]125Historical resolution of EtherRAT C2 domain itemrange[.]com.
IPV438[.]110[.]228[.]33Exposed directory containing artifacts assessed as linked to a The Gentlemen victim.
IPV438[.]110[.]228[.]43Historical resolution of EtherRAT C2 domain wiselystarting[.]com.
IPV450[.]114[.]167[.]112Historical resolution of EtherRAT C2 domain simultaneouslypower[.]com.
IPV477[.]110[.]122[.]137Case-observed The Gentlemen infrastructure with an exposed directory containing Linux-intrusion artifacts.
IPV477[.]110[.]122[.]58Staging server associated with a related EtherRAT MSI and Sliver C2.
IPV477[.]110[.]126[.]46Secondary controller embedded in Go reverse shells.
SHA25673955566338adffb423c3b7608792963080da780e8b7b2c2cd6b6b0cef6f217fXOR-encrypted EtherRAT backdoor jlfYWzAkN99jpGu.xml.
SHA2567567994310a9576b1f98dc672ecfa038f1d65084315f59e3883f9b6f24000073EtherRAT decoder and Run-key persistence component YUGKag9mvNKWylo.bin.
SHA256756c2096f54c5497110c9d854625c3ed592873e566d532077cd7adb4d10d4addMulti-controller Go reverse shell ws_3srv.exe.
SHA25686881b8e9d197ac2f734792de48d5dfaebe7cafb6e35d49c5dd7fe6eb697230eDecoded Node.js EtherRAT payload BDQbS2lZ6u.bak.
SHA256bd61c2880920bbfb86c12df439dd1ca0258a10e532433698fd029aef2a5b33f2Standalone Garble-obfuscated Sliver implant svchost_update.exe.
SHA256c7a80576fbd25057435652788591d13998da272edf627fc29d296684cefc50e5Embedded Sliver implant VOCATIONAL_GORILLA extracted from the shellcode.
SHA256ee6807a8abfabced22ee026e178a28da64d13cc3408e224394ff6e5782fb9e1dEtherRAT installer cons_c1.0.1.msi deployed by remote scheduled tasks.
SHA256f4c87a1df04274b7497cbf9a4619b946c915cf5210b6e2eaa2fee1629f4ff196Identical multi-controller Go reverse shells update.exe and ws_stable.exe.
SHA256f609621698eaad8c4683750fe8bd0e242349be3eea408da593151ff877ed8ab6Malicious task_39.ps1 script used for account creation, defense impairment, credential theft, tunneling, and reverse shells.
SHA256f659681525debda69fe0865b2b27a42f684b1fda66aa7398e80b84cc765c73c7Node.js bootstrapper jEdb5ROX.cmd installed by the EtherRAT MSI.
SHA256fb94688ed37dfcb985a8a4d720230e5150956e1788d579b0a54b53a153fd2f2eSGN/Donut-packaged Sliver beacon shellcode slv_beacon_sc.bin.
URLhxxp[:]//193[.]233[.]202[.]17:42718/task_39[.]ps1Staging URL from which a scheduled task downloaded the malicious PowerShell script.
URLhxxp[:]//193[.]233[.]202[.]17:8088/slv_beacon_sc[.]binURL used by inject_sliver.ps1 to download Sliver beacon shellcode.
URLhxxps[:]//193[.]233[.]202[.]17/C2 endpoint in the recovered Sliver implant configuration.
URLhxxps[:]//itemrange[.]com/Historical EtherRAT C2 URL returned by the Ethereum contract.
URLhxxps[:]//publisherresolution[.]com/Historical EtherRAT C2 URL returned by the Ethereum contract.
URLhxxps[:]//resumeacceptable[.]com/Historical EtherRAT C2 URL returned by the Ethereum contract.
URLhxxps[:]//simultaneouslypower[.]com/Historical EtherRAT C2 URL returned by the Ethereum contract.
URLhxxps[:]//wiselystarting[.]com/Historical EtherRAT C2 URL returned by the Ethereum contract.

MITRE ATT&CK

T1003.002 · Security Account Managertask_39.ps1 exports the SAM, SYSTEM, and SECURITY registry hives and uploads them to actor infrastructure.T1021.002 · SMB/Windows Admin SharesDeployment scripts copy payloads to remote administrative shares.T1047 · Windows Management Instrumentationdeploy.cmd uses remote wmic process call create as a fallback to launch certutil.exe.T1053.005 · Scheduled TaskRemote scheduled tasks, including WinSvcUpdate2, execute deployment payloads.T1059.001 · PowerShellHidden PowerShell download cradles execute task_39.ps1, and PowerShell loads Sliver shellcode.T1059.003 · Windows Command ShellDeployment batch files and custom Go backdoors execute commands through cmd.exe.T1059.007 · JavaScriptNode.js executes the decoded EtherRAT JavaScript backdoor and evaluates JavaScript received from C2.T1071.001 · Web ProtocolsEtherRAT polls C2 over HTTP(S); payload staging, registry-hive uploads, and Sliver C2 also use web protocols.T1102.001 · Dead Drop ResolverEtherRAT queries an Ethereum smart contract through public RPC services to retrieve its current C2 domain.T1105 · Ingress Tool Transfercertutil.exe, PowerShell WebClient, and curl.exe retrieve scripts, installers, shellcode, and other payloads.T1112 · Modify RegistryIntrusion scripts modify RDP and UAC-related registry settings; EtherRAT creates a Run value.T1136.001 · Local Accounttask_39.ps1 and other recovered payloads create the local account support2.T1136.002 · Domain Accountadduser.ps1 creates the svcadm Active Directory account; task_39.ps1 also attempts to create support2 in the domain.T1218.007 · Msiexecmsiexec.exe silently installs the EtherRAT MSI on remote hosts.T1547.001 · Registry Run Keys / Startup FolderEtherRAT creates the WindowsHost Run value to launch its Node.js payload through headless conhost.exe.T1562.001 · Disable or Modify Toolstask_39.ps1 stops and disables ESET services, while fix_uac.bat disables UAC.T1572 · Protocol TunnelingChisel is configured to establish reverse SOCKS tunnels to 193.233.202[.]17.T1620 · Reflective Code Loadinginject_sliver.ps1 loads downloaded Sliver shellcode into executable memory and starts it with CreateThread.

CVE

Threat Actors

Malware

Vendors

Products

Tools

AttackCapturethe Hunt.io platform we can see this IP has been is linked to Sliver malware on port 31337, with AttackCapture entries exposing the threat actors infrastructure:ChiselC2 layers, the toolkit covered credential theft (Mimikatz, registry-hive and LSASS dumping), tunneling (Chisel, Ligolo-ng), and Potato-family privilege escalation, showing an operator equipped for the full path toGodPotatoSeveral privilege-escalation scripts were observed. gp_reflect.ps1 loads a GodPotato payload in memory and changes LocalAccountTokenFilterPolicy. fix_uac.bat disables UAC and changes the same policy. ms16032.ps1Hunt.ioMay 21st write-up on The Gentlemen's defense evasion TTPs. Both IPs showed up as open directories on the Hunt.io platform through the IOC Hunter feature. On June 16th, Huntress also published a ClickFix campaign thatIOC Hunterdefense evasion TTPs. Both IPs showed up as open directories on the Hunt.io platform through the IOC Hunter feature. On June 16th, Huntress also published a ClickFix campaign that deployed EtherRAT. ThatJuicyPotatojp.exe - JuicyPotato x64 exploitLigolo-ngthe toolkit covered credential theft (Mimikatz, registry-hive and LSASS dumping), tunneling (Chisel, Ligolo-ng), and Potato-family privilege escalation, showing an operator equipped for the full path to domain-wideMimikatzBeyond the C2 layers, the toolkit covered credential theft (Mimikatz, registry-hive and LSASS dumping), tunneling (Chisel, Ligolo-ng), and Potato-family privilege escalation, showing an operator equipped for the fullPrintSpooferps64.exe - PrintSpoofer x64 exploit

Countries

Related Articles