EtherRAT has surfaced in a Windows domain intrusion tied to an affiliate of the Gentlemen ransomware operation. The campaign shows how a single foothold can become a network-wide problem when attackers gain privileged access.
The operators used remote scheduled tasks to push malicious installer packages to other systems.
Those installers deployed EtherRAT, a remote access tool built around Node.js that can receive instructions, steal access, and keep running after the initial compromise.
Recent reporting on EtherRAT blockchain hiding techniques shows why this design can make tracking its infrastructure harder.
Analysts at Hunt.io identified the activity after finding an exposed directory on a server used during the intrusion.
The collection contained scripts, task configurations, installers, tunnelling tools, and reverse shells, offering an unusually detailed view of an active operator toolkit.
Hunt.io said in a report shared with Cyber Security News (CSN) that the evidence points to an effort to preserve several routes back into a victim environment while collecting credentials and Active Directory data.
That combination raises the risk of rapid disruption across connected systems, particularly because one compromised administrator account can turn into broad domain control.
Similar ransomware attacks targeting Windows domains have relied on the same advantage.
Remote Scheduled Tasks Spread EtherRAT
The attackers used administrative shares, Windows Management Instrumentation, and remote task registration to reach internal hosts.
Scripts copied payloads to remote machines, then created tasks with names such as WinSvcUpdate2 and WindowsUpdSvc to make the activity appear routine.
This is a practical reminder that Windows task scheduler abuse is not only a persistence trick, but also a delivery method for lateral movement.
One task ran under the SYSTEM account and downloaded a PowerShell script from the staging server.
The script created a local administrator account, attempted to add it to Domain Admins, disabled security services, exported registry hives, and set up a tunnel for remote access.
.webp)
It also staged reverse-shell tooling, giving the operator backup options if one access route failed.
The deployment scripts used certutil.exe, a legitimate Windows utility, to retrieve an MSI package, then invoked msiexec.exe to install it quietly.
A fallback path copied the installer through SMB. This blend of built-in tools and administrative access can look like ordinary system work unless teams review task-creation events, unusual remote share writes, and unexpected processes launched through task scheduler.
The recovered files linked the activity to the Gentlemen cluster. The attribution is an assessment, but the shared tooling, installer naming, and infrastructure provide strong context for defenders investigating related incidents.
Blockchain C2 Extends Access
After installation, EtherRAT decrypts a JavaScript backdoor and establishes a Run-key entry so it launches again when the user signs in.
If Node.js is unavailable, the installer downloads a runtime first. The malware then disguises its web requests with random paths and common-looking file extensions while polling for instructions.
Its most distinctive feature is where it finds its command server. Instead of keeping a single address inside the malware, EtherRAT queries an Ethereum smart contract for the current domain.
The operator can change that destination without replacing the implant, while investigators can examine the contract history to reconstruct earlier domains. Earlier coverage of EtherRAT malicious MSI installers documented the malware’s growing Windows focus.
.webp)
Any server response longer than ten characters can be treated as JavaScript and executed by the implant.
That gives the operator a flexible way to run commands, access files, start processes, contact the network, or pull in new payloads without a fixed feature set. The custom X-Bot-Server HTTP header is a useful detection clue for security teams.
Defenders should urgently review scheduled tasks created remotely, especially those running as SYSTEM or calling PowerShell, certutil, msiexec, or files outside normal application paths.
They should also investigate new privileged accounts, security-service changes, outbound traffic to public Ethereum RPC services, and connections to the infrastructure listed below.
Isolating affected hosts, resetting exposed credentials, and checking for Run-key persistence can help contain a suspected spread before it reaches more systems.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| IP address | 193.233.202.17 | Primary staging, C2, Sliver, tunnelling, and registry-hive exfiltration server |
| IP address | 146.103.127.44 | Secondary controller embedded in Go reverse-shell binaries |
| IP address | 77.110.126.46 | Secondary controller embedded in Go reverse-shell binaries |
| IP address | 77.110.122.137 | Case-observed Gentlemen infrastructure |
| IP address | 77.110.122.58 | Staging server associated with cons1.0.1.msi |
| IP address | 38.110.228.43 | Historical resolution for wiselystarting.com |
| IP address | 38.110.228.125 | Historical resolution for itemrange.com |
| IP address | 38.110.228.33 | Open directory containing disclosed Gentlemen victim artifacts |
| IP address | 185.117.72.215 | Historical resolution for resumeacceptable.com |
| IP address | 185.45.193.151 | Historical resolution for publisherresolution.com |
| IP address | 50.114.167.112 | Historical resolution for simultaneouslypower.com |
| Domain | itemrange.com | Historical EtherRAT C2 domain from the Ethereum contract |
| Domain | wiselystarting.com | Historical EtherRAT C2 domain from the Ethereum contract |
| Domain | simultaneouslypower.com | Historical EtherRAT C2 domain from the Ethereum contract |
| Domain | resumeacceptable.com | Historical EtherRAT C2 domain from the Ethereum contract |
| Domain | publisherresolution.com | Historical EtherRAT C2 domain from the Ethereum contract |
| URL | hxxp://193.233.202.17:42718/task39.ps1 | PowerShell payload download location |
| URL | hxxp://193.233.202.17:8088/slvbeaconsc.bin | Sliver shellcode download location |
| URL | hxxps://193.233.202.17 | Sliver C2 endpoint |
| Ethereum contract | 0xb3f2897f2bc797e5b9033faef8c81e92b01cb831 | EtherRAT C2 resolver contract |
| Ethereum lookup key | 0x40b57c3622c1CbfD699207F71F2dE5A8Fe256893 | Smart-contract lookup key |
| HTTP header | X-Bot-Server | EtherRAT network detection indicator |
| File name | consc1.0.1.msi | EtherRAT installer deployed by remote scheduled tasks |
| SHA-256 | EE6807A8ABFABCED22EE026E178A28DA64D13CC3408E224394FF6E5782FB9E1D | Hash of consc1.0.1.msi |
| File name | jEdb5ROX.cmd | Node.js bootstrapper installed by the EtherRAT MSI |
| SHA-256 | F659681525DEBDA69FE0865B2B27A42F684B1FDA66AA7398E80B84CC765C73C7 | Hash of jEdb5ROX.cmd |
| File name | YUGKag9mvNKWylo.bin | EtherRAT decoder and Run-key persistence component |
| SHA-256 | 7567994310A9576B1F98DC672ECFA038F1D65084315F59E3883F9B6F24000073 | Hash of YUGKag9mvNKWylo.bin |
| File name | jlfYWzAkN99jpGu.xml | XOR-encrypted EtherRAT backdoor |
| SHA-256 | 73955566338ADFFB423C3B7608792963080DA780E8B7B2C2CD6B6B0CEF6F217F | Hash of jlfYWzAkN99jpGu.xml |
| File name | BDQbS2lZ6u.bak | Decoded Node.js EtherRAT payload |
| SHA-256 | 86881B8E9D197AC2F734792DE48D5DFAEBE7CAFB6E35D49C5DD7FE6EB697230E | Hash of BDQbS2lZ6u.bak |
| File name | task39.ps1 | Account creation, defence impairment, hive theft, tunnelling, and reverse-shell script |
| Hash | F609621698EAAD8C4683750FE8BD0E2423 | Hash listed for task39.ps1 |
| File name | slvbeaconsc.bin | SGN/Donut-packed Sliver beacon shellcode |
| SHA-256 | FB94688ED37DFCB985A8A4D720230E5150956E1788D579B0A54B53A153FD2F2E | Hash of slvbeaconsc.bin |
| File name | VOCATIONALGORILLA | Sliver implant extracted from shellcode |
| SHA-256 | C7A80576FBD25057435652788591D13998DA272EDF627FC29D296684CEFC50E5 | Hash of extracted Sliver implant |
| File name | svchostupdate.exe | Standalone Garble-obfuscated Sliver implant |
| SHA-256 | BD61C2880920BBFB86C12DF439DD1CA0258A10E532433698FD029AEF2A5B33F2 | Hash of svchostupdate.exe |
| File names | update.exe, wsstable.exe | Duplicate multi-controller Go reverse shells |
| SHA-256 | F4C87A1DF04274B7497CBF9A4619B946C915CF5210B6E2EAA2FEE1629F4FF196 | Hash of the duplicate Go reverse-shell binaries |
| File name | ws3srv.exe | Multi-controller Go reverse shell |
| SHA-256 | 756C2096F54C5497110C9D854625C3ED592873E566D532077CD7ADB4D10D4ADD | Hash of ws3srv.exe |
| Scheduled-task names | WinSvcUpdate2, WindowsUpdSvc31, WindowsUpdateSvc, SysUpdate | Malicious remote scheduled-task names |
| File path | C:upd.exe | Go reverse shell staged by task39.ps1 |
| File path | C:37.exe | Privileged reverse shell launched by getsys.exe |
| Artifact | APPDATA.log | EtherRAT runtime log |
| Artifact | APPDATA.nodebotid | EtherRAT configuration and bot identifier |
| Registry artifact | HKCU Run key | EtherRAT persistence location |
| Credential | support2 : Supp0rt22026! | Account credentials created or used by intrusion tooling |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Building Resilience Against Phishing & Malware and Analyze it in a safe environment – Power your SOC with ANY.RUN

