The technique has been linked to an affiliate of The Gentlemen ransomware operation, which deployed a Node. js backdoor known as EtherRAT during intrusions targeting Windows networks. Instead of storing a fixed command server inside the malware, EtherRAT reads a smart contract on the Ethereum blockchain to obtain an active domain.
The arrangement allows operators to replace compromised or blocked infrastructure without rebuilding and redistributing the malware. They can update data held by the smart contract, directing infected computers towards a different server while retaining the same blockchain address in the implant.
Evidence of the operation emerged from an exposed server directory associated with infrastructure previously connected to The Gentlemen. The material offered a detailed view of an intrusion toolkit used for persistent access, credential theft, remote control and movement between systems.
The affiliate created a privileged Windows account named “support2” and established scheduled tasks capable of launching PowerShell commands. Those tasks downloaded and executed malicious Microsoft Installer packages on remote machines, helping the attackers spread their tools across the targeted environment.
One installer deployed EtherRAT alongside Sliver shellcode and several Go-based programs. Sliver is a command-and-control framework that can provide operators with an additional route into compromised networks. The Go binaries included reverse-shell capabilities, creating further channels for issuing commands and maintaining access.
The toolkit also contained material associated with extracting credentials from the Local Security Authority Subsystem Service, or LSASS. This Windows process stores sensitive authentication information in memory. Successful access can expose password hashes, tokens and other credentials that may enable attackers to impersonate users or compromise domain accounts.
Other components were designed to interfere with endpoint security products and establish encrypted tunnels from affected systems. The combination indicates that EtherRAT was not being used as an isolated backdoor. It formed part of a wider operation aimed at gaining administrative control before data theft and ransomware deployment.
Infrastructure analysis connected the activity to several internet protocol addresses and hosting networks. Some servers exposed open directories containing payloads, victim artefacts and operational files. Closely named installer packages found on separate systems used the same Ethereum smart contract, strengthening the assessment that they belonged to a common campaign.
The Gentlemen operation has also been associated with TukTuk, another command-and-control framework observed during ransomware intrusions. Attackers have combined such frameworks with legitimate remote-management software, allowing malicious activity to blend with tools commonly used by corporate support teams.
EtherRAT has appeared through more than one delivery route. Campaigns have distributed installers disguised as trusted administrative utilities, targeting system administrators, security specialists and DevOps personnel who hold elevated network privileges. Other activity has used deceptive verification prompts or software-download pages to persuade users to run malicious commands.
Once installed, the backdoor can gather system and domain information, inspect running processes and identify security products. It generates web requests that resemble ordinary image, stylesheet or icon downloads, using varied file extensions and query parameters to reduce the likelihood that routine traffic monitoring will flag a consistent pattern.
The use of public blockchains for malware coordination is broader than a single ransomware group. Other criminal operations have stored proxy addresses or malicious code in smart contracts on Ethereum, Polygon and BNB Smart Chain. State-linked attackers have also adopted blockchain-based delivery methods to make malicious infrastructure harder to remove.
Blockchain records are distributed across many independent nodes, leaving no central server that defenders can seize to erase the stored information. Reading data from a contract may also require no new blockchain transaction, limiting the visible financial activity that investigators could otherwise follow.
The smart contract does not necessarily host the final ransomware or backdoor. In EtherRAT infections, it functions as a durable resolver that tells the implant where to connect. The attacker-controlled server can then provide commands, additional code or reconnaissance modules.
Defenders can still disrupt the chain by blocking identified domains and internet protocol addresses, removing scheduled tasks, inspecting unusual installer activity and restricting unauthorised PowerShell execution. Monitoring calls to public blockchain interfaces from devices that have no business need for them can also reveal suspicious behaviour.
Follow Arabian Post
Select Arabian Post as your preferred source on Google and MSN News for trusted business news and Arab politics and updates.