The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2

News

Defensive-leaning breakdown of a The Gentlemen intrusion recovered from an exposed open directory. Detection surface worth noting: X-Bot-Server HTTP header on EtherRAT polling traffic Scheduled task names: WinSvcUpdate2, WindowsUpdSvc31, WindowsUpdateSvc, SysUpdate LOLBAS chain: certutil.exe fetches the MSI, msiexec.exe installs silently Run-key WindowsHost under HKCU launching Node.js through headless conhost.exe ESET service tampering via sc.exe across eight named services EtherRAT install path %LOCALAPPDATA%MicrosoftSltt and log at %APPDATA%svchost.log Full detail, MITRE mapping and IOCs: https://hunt.io/blog/the-gentlemen-etherrat-ethereum-smart-contract-c2 . submitted by /u/Straight-Practice-99 [link] [comments]Technical Information Security Content & DiscussionRead More