Researchers linked a The Gentlemen ransomware affiliate to a Windows domain intrusion in which operators deployed EtherRAT, a Node.js-based implant that retrieves command-and-control infrastructure from an Ethereum smart contract and can execute arbitrary JavaScript returned by its server. The activity was reconstructed from an exposed open directory on 193.233.202[.]17, which captured tooling for persistence, credential theft, lateral movement, and remote access. Investigators said the intrusion used a broad post-exploitation stack including Sliver, custom Go reverse shells, Chisel, Ligolo-ng, Mimikatz, and Potato privilege-escalation tools, indicating preparation for domain-wide ransomware operations.
The operators reportedly used LOLBAS techniques to spread the malware across Windows systems, including certutil.exe to fetch an MSI package and msiexec.exe to install it silently through remote scheduled tasks. Persistence included scheduled tasks and a Run key named WindowsHost, while defenders were also given indicators such as ESET service tampering, an unusual X-Bot-Server HTTP header in EtherRAT polling traffic, and specific filesystem artifacts. Infrastructure analysis connected the staging server to additional controllers at 146.103.127[.]44 and 77.110.126[.]46, plus a related EtherRAT node at 77.110.122[.]58 using the same Ethereum contract, strengthening attribution to The Gentlemen and providing detection opportunities for defenders.

Get the actors, campaigns, and ATT&CK mapping behind it.
13 events from the most recent confirmed update back to the earliest known activity.
Artifacts in the recovered intrusion toolkit were linked to an American victim that The Gentlemen had disclosed. The source explicitly anchors that victim disclosure to 9 May.
Infrastructure clustering tied the staging server at 193.233.202[.]17 to additional controllers at 146.103.127[.]44 and 77.110.126[.]46, as well as a related EtherRAT cluster on 77.110.122[.]58 using the same Ethereum contract. The overlaps supported attribution of the activity to The Gentlemen.
By analyzing blockchain updates, researchers reconstructed five historical EtherRAT command-and-control domains: publisherresolution[.]com, resumeacceptable[.]com, simultaneouslypower[.]com, wiselystarting[.]com, and itemrange[.]com. The same analysis identified the malware's custom X-Bot-Server polling header and host artifacts such as %APPDATA%\svchost.log.
Researchers found that the decrypted EtherRAT payload resolved its active command-and-control domain from Ethereum smart contract 0xb3f2897f2bc797e5b9033faef8c81e92b01cb831. The malware queried the contract with a specific lookup key and function selector, then executed JavaScript returned by its server.
The MSI dropped Node.js bootstrap and EtherRAT components into %LOCALAPPDATA%\MicrosoftSltt. Persistence was established through the HKCU Run key WindowsHost, which launched the payload via a headless conhost.exe process.
Recovered deployment scripts created remote scheduled tasks such as WinSvcUpdate2 and used certutil.exe to fetch an MSI, with msiexec.exe then installing it silently. A related deployment path also copied the MSI over SMB and used WMIC with certutil.exe as a fallback.
The intrusion used administrative shares, xcopy, schtasks, services, and WMI for lateral movement across internal hosts. These mechanisms were part of the operator's effort to spread tooling through the Windows environment.
The recovered toolkit included Sliver shellcode delivery, custom Go reverse shells, Chisel, Ligolo-ng, and multiple Potato-family privilege-escalation tools. These artifacts indicate a broader post-exploitation stack beyond the EtherRAT deployment.
The acl_enum.ps1 script impersonated an interactive Windows token to query Active Directory users, computers, and groups. It also requested the legacy LAPS attribute ms-Mcs-AdmPwd.
Recovered scripts showed the actor exporting the SAM, SYSTEM, and SECURITY hives and exfiltrating them over HTTP PUT requests. Another script invoked MiniDumpWriteDump against LSASS to obtain credentials.
The intrusion used sc.exe to stop and disable multiple ESET services. One source specifies that eight named ESET services were targeted for tampering.
A recovered scheduled-task chain downloaded task_39.ps1 and ran it as SYSTEM. The script created a local administrator account named support2, added it to Administrators and Remote Desktop Users, and attempted to add it to Domain Admins.
Researchers found an exposed open directory on 193.233.202[.]17 containing 82 files that captured an intrusion operator linked to The Gentlemen ransomware. The recovered toolkit documented persistence, credential theft, lateral movement, and EtherRAT deployment across a Windows domain.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 37 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcereddit.com
Open sourcehunt.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.