The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2

    Date: 08/05/2026

    Severity: High

    Summary

    The Gentlemen ransomware affiliate used LOLBAS techniques, scheduled tasks, and MSI payloads to deploy EtherRAT across Windows networks for persistent access, credential theft, privilege escalation, and lateral movement. EtherRAT retrieves its command-and-control (C2) domains from an Ethereum smart contract, enabling dynamic infrastructure rotation and arbitrary JavaScript execution through a Node.js runtime. The operator’s toolkit also included Mimikatz, LSASS dumping, Sliver, Chisel, Ligolo-ng, and Potato-family privilege escalation tools, demonstrating capabilities to achieve domain-wide ransomware deployment. 

    Indicators of Compromise (IOC) List

    Domains/URLs

    itemrange.com

    wiselystarting.com

    simultaneouslypower.com

    resumeacceptable.com

    publisherresolution.com

    IP Address

    193.233.202.17

    146.103.127.44

    77.110.126.46

    77.110.122.137

    77.110.122.58

    38.110.228.43

    38.110.228.125

    38.110.228.33

    185.117.72.215

    185.45.193.151

    50.114.167.112

    Hash

    EE6807A8ABFABCED22EE026E178A28DA64D13CC3408E224394FF6E5782FB9E1D

    F659681525DEBDA69FE0865B2B27A42F684B1FDA66AA7398E80B84CC765C73C7

    7567994310A9576B1F98DC672ECFA038F1D65084315F59E3883F9B6F24000073

    73955566338ADFFB423C3B7608792963080DA780E8B7B2C2CD6B6B0CEF6F217F

    86881B8E9D197AC2F734792DE48D5DFAEBE7CAFB6E35D49C5DD7FE6EB697230E

    F609621698EAAD8C4683750FE8BD0E242349BE3EEA408DA593151FF877ED8AB6

    FB94688ED37DFCB985A8A4D720230E5150956E1788D579B0A54B53A153FD2F2E

    C7A80576FBD25057435652788591D13998DA272EDF627FC29D296684CEFC50E5

    BD61C2880920BBFB86C12DF439DD1CA0258A10E532433698FD029AEF2A5B33F2

    F4C87A1DF04274B7497CBF9A4619B946C915CF5210B6E2EAA2FEE1629F4FF196

    756C2096F54C5497110C9D854625C3ED592873E566D532077CD7ADB4D10D4ADD

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "publisherresolution.com" or url like "publisherresolution.com" or siteurl like "publisherresolution.com" or domainname like "itemrange.com" or url like "itemrange.com" or siteurl like "itemrange.com" or domainname like "wiselystarting.com" or url like "wiselystarting.com" or siteurl like "wiselystarting.com" or domainname like "simultaneouslypower.com" or url like "simultaneouslypower.com" or siteurl like "simultaneouslypower.com" or domainname like "resumeacceptable.com" or url like "resumeacceptable.com" or siteurl like "resumeacceptable.com"

    Detection Query 2 :

    dstipaddress IN ("38.110.228.33","185.45.193.151","77.110.122.137","77.110.126.46","38.110.228.43","146.103.127.44","50.114.167.112","38.110.228.125","193.233.202.17","77.110.122.58","185.117.72.215") or srcipaddress IN ("38.110.228.33","185.45.193.151","77.110.122.137","77.110.126.46","38.110.228.43","146.103.127.44","50.114.167.112","38.110.228.125","193.233.202.17","77.110.122.58","185.117.72.215")

    Detection Query 3 :

    sha256hash IN ("F4C87A1DF04274B7497CBF9A4619B946C915CF5210B6E2EAA2FEE1629F4FF196","BD61C2880920BBFB86C12DF439DD1CA0258A10E532433698FD029AEF2A5B33F2","FB94688ED37DFCB985A8A4D720230E5150956E1788D579B0A54B53A153FD2F2E","EE6807A8ABFABCED22EE026E178A28DA64D13CC3408E224394FF6E5782FB9E1D","F659681525DEBDA69FE0865B2B27A42F684B1FDA66AA7398E80B84CC765C73C7","7567994310A9576B1F98DC672ECFA038F1D65084315F59E3883F9B6F24000073","73955566338ADFFB423C3B7608792963080DA780E8B7B2C2CD6B6B0CEF6F217F","86881B8E9D197AC2F734792DE48D5DFAEBE7CAFB6E35D49C5DD7FE6EB697230E","F609621698EAAD8C4683750FE8BD0E242349BE3EEA408DA593151FF877ED8AB6","C7A80576FBD25057435652788591D13998DA272EDF627FC29D296684CEFC50E5","756C2096F54C5497110C9D854625C3ED592873E566D532077CD7ADB4D10D4ADD")

    Reference:    

    https://hunt.io/blog/the-gentlemen-etherrat-ethereum-smart-contract-c2#IOCs_and_Observables                        


    Tags

    Credential HarvestingMimikatzChiselPotatoRATMalwareThreat ActorRansomwareLOLBAS

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags