Gambit Security: Ransomware Hackers Are Hiding Malware Command Servers Inside Ethereum Smart Contracts

Gambit Security: Ransomware Hackers Are Hiding Malware Command Servers Inside Ethereum Smart Contracts

Gentlemen Ransomware Affiliate Leverages Ethereum Smart Contracts for Stealthy C2 Operations

A Gentlemen ransomware affiliate has adopted a novel tactic to evade detection, using Ethereum smart contracts to dynamically resolve command-and-control (C2) domains via the EtherRAT backdoor. Unlike traditional malware that hardcodes C2 infrastructure, this campaign queries public Ethereum RPC endpoints including Tenderly, Flashbots, MEVBlocker, and PublicNode to fetch rotating domains from an on-chain contract, ensuring resilience against takedowns.

The attack chain begins with MSI payloads (cons_c1.0.1.msi, cons_1.0.1.msi) deployed via remote scheduled tasks. Once executed, EtherRAT a Node.js-based trojan decrypts an XOR-encoded backdoor, establishes persistence via a Run key ("WindowsHost"), and launches in headless mode through conhost.exe. The malware avoids fixed infrastructure by embedding a smart contract lookup key, resolving C2 domains such as publisherresolution[.]com, resumeacceptable[.]com, and wiselystarting[.]com, mirroring tactics seen in prior EtherHiding supply-chain attacks.

Post-exploitation tools include LSASS and registry-hive dumping, ESET service tampering, and reverse shells (Sliver, Go-based binaries) for lateral movement. Operators use SOCKS proxies (Chisel, Ligolo-ng) and UUID-based bot tracking to maintain persistence across sessions. Beacon traffic mimics benign static asset requests (e.g., png, css, ico) with randomized paths, while a custom "X-Bot-Server" header identifies resolved controllers an indicator previously linked to DPRK-adjacent campaigns.

An exposed open directory (193.233.202[.]17) revealed 82 artifacts (145 MB) reconstructing the full intrusion, including PowerShell bootstraps, a privileged account (support2:Supp0rt2@2026!), and multi-stage payloads (pb39_new.exe, update.exe). The infrastructure spans AS203273 (NetCrafters OU, Estonia) and AS174 (Cogent Communications, US), with historical ties to AEZA ASN ranges. Additional C2s (38.110.228[.]43, 38.110.228[.]125) align with a Gambit Security-documented Gentlemen ransomware case, reinforcing the link between blockchain-anchored C2 and this ransomware ecosystem.

The use of on-chain domain rotation provides attackers with takedown-resistant agility, while defenders gain a permanent ledger of historical C2s a double-edged sword for attribution and mitigation.

Source: https://gbhackers.com/ethereum-smart-contracts/

Gambit Security TPRM report: https://www.rankiteo.com/company/gambit-cyber

"id": "gam1785918249",
"linkid": "gambit-cyber",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'attack_vector': 'Malicious MSI payloads deployed via remote scheduled tasks',
 'data_breach': {'sensitivity_of_data': 'High (privileged credentials, system '
                                        'configuration data)',
                 'type_of_data_compromised': ['LSASS dumps',
                                              'Registry hives',
                                              'Privileged account '
                                              'credentials']},
 'description': 'A Gentlemen ransomware affiliate has adopted a novel tactic '
                'to evade detection, using Ethereum smart contracts to '
                'dynamically resolve command-and-control (C2) domains via the '
                'EtherRAT backdoor. The attack chain begins with MSI payloads '
                'deployed via remote scheduled tasks, leading to the '
                'deployment of EtherRAT, a Node.js-based trojan that decrypts '
                'an XOR-encoded backdoor and establishes persistence. The '
                'malware uses smart contracts to resolve rotating C2 domains, '
                'ensuring resilience against takedowns. Post-exploitation '
                'tools include LSASS and registry-hive dumping, reverse '
                'shells, and SOCKS proxies for lateral movement. The '
                'infrastructure spans multiple ASNs with historical ties to '
                'ransomware ecosystems.',
 'impact': {'data_compromised': 'LSASS dumps, registry hives, privileged '
                                'account credentials',
            'identity_theft_risk': 'High (privileged account credentials '
                                   'compromised)',
            'operational_impact': 'Lateral movement, persistence '
                                  'establishment, potential data exfiltration'},
 'initial_access_broker': {'backdoors_established': 'EtherRAT (Node.js-based '
                                                    'trojan)',
                           'entry_point': 'MSI payloads via remote scheduled '
                                          'tasks'},
 'motivation': 'Financial gain (ransomware)',
 'post_incident_analysis': {'root_causes': 'Use of Ethereum smart contracts '
                                           'for C2 domain resolution, lack of '
                                           'detection for blockchain-based C2 '
                                           'infrastructure'},
 'ransomware': {'ransomware_strain': 'Gentlemen Ransomware'},
 'references': [{'source': 'Cyber Incident Report'}],
 'threat_actor': 'Gentlemen Ransomware Affiliate',
 'title': 'Gentlemen Ransomware Affiliate Leverages Ethereum Smart Contracts '
          'for Stealthy C2 Operations',
 'type': 'Ransomware'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.