
The Gentlemen Ransomware Affiliate Deploys EtherRAT via Ethereum Smart Contract C2
An exposed directory on 193.233.202[.]17 has revealed a detailed intrusion toolkit linked to a suspected affiliate of The Gentlemen ransomware operation. The recovered files show an operator preparing to gain long-term access to Windows networks, steal credentials, disable security products, move across the domain, and deploy several command-and-control (C2) channels. The directory contained 82 files […]
The post The Gentlemen Ransomware Affiliate Deploys EtherRAT via Ethereum Smart Contract C2 appeared first on Cyber Security News.