Threat activity tracked as UTA-2026-024 compromised an unnamed U.S. organization through an exposed server and established durable control of its Windows Active Directory environment. Operators deployed a Sliver C2 beacon, created privileged accounts, stole credentials by harvesting registry hives and dumping LSASS memory, and used remote administration capabilities. They disabled endpoint-protection services, enabled RDP while disabling Network Level Authentication, and altered DNS filtering and internal DNS settings to permit command-and-control traffic.
A Node.js implant obtained its C2 domain from an Ethereum smart contract, whose domain value changed five times in five months, frustrating conventional domain-based blocking while leaving the contract as a stable tracking artifact. The attackers also used SYSTEM-level scheduled tasks to retrieve payloads without maintaining a fixed local payload. Although associated infrastructure was linked to a confirmed ransomware incident, investigators found no evidence of ransomware deployment in this intrusion and have not attributed the activity to a specific actor.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
The historical operator-used address 146.103.127.44 was observed and designated monitor-only in reporting on UTA-2026-024 infrastructure.
Researchers linked the campaign infrastructure to a confirmed ransomware incident, but found no evidence that ransomware or another encryptor was deployed during the UTA-2026-024 intrusion and did not identify the operators.
A Node.js implant resolved its C2 domain through Ethereum smart contract 0xb3f2897f2bc797e5b9033faef8c81e92b01cb831. The contract's domain value changed five times over five months while its public contract address remained unchanged.
The operators allowlisted an attacker-controlled domain through the victim's DNS content-filter administration interface and created a corresponding internal DNS record. The first Ethereum-contract C2 domain, publisherresolution.com, was inserted into the victim's DNS configuration.
Operators staged from an exposed server and used a Sliver beacon and Active Directory-focused toolkit against one unnamed U.S. organization, with a planned rollout across 18 hosts. They created privileged accounts, weakened RDP authentication, disabled eight endpoint-protection services, stole registry and LSASS credentials, and established SYSTEM-level scheduled-task persistence.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.