
The Gentlemen Threat Actor Uses Ethereum Smart Contracts to Deploy EtherRAT on Windows Networks
cybersecuritymalwareEtherRATEthereumthreat_actorWindowsC2LOLBAS
The post details an intrusion by the threat actor 'The Gentlemen,' who deploys EtherRAT malware on Windows networks using Ethereum smart contracts for command and control (C2). Key indicators include an X-Bot-Server HTTP header in polling traffic, scheduled tasks named WinSvcUpdate2, WindowsUpdSvc31, WindowsUpdateSvc, and SysUpdate, and a LOLBAS chain using certutil.exe and msiexec.exe. The malware installs to %LOCALAPPDATA%\MicrosoftSltt with logs at %APPDATA%\svchost.log, and tampering with ESET services via sc.exe was observed.