• Latest
Ransomware operators turn Ethereum into hidden command channel — Arabian Post

Ransomware operators turn Ethereum into hidden command channel — Arabian Post

August 6, 2026

D Gukesh Inspires Indian Men’s Chess Team To Crucial Win At 46th Olympiad

September 26, 2026

Indonesia proposes nearly 24M hectares of new Marine Protected Areas

September 26, 2026

Israeli shelling continues as Lebanon’s PM demands withdrawal in UN speech | Israel attacks Lebanon News

September 25, 2026

SG man who feels he wasted his 20s asks netizens: Is it too late to turn life around?

September 25, 2026

Kawanthissa Has Not Been Shot – Sri Lanka Mirror – Right to Know. Power to Change

September 25, 2026

Civil-military leadership making joint efforts to strengthen economy: PM Shehbaz

September 25, 2026

Japanese skateboarders grab gold at Asian Games

September 26, 2026

India needs diversified energy routes, wider trade partnerships amid geopolitical risks: Economist

September 26, 2026

Trump perlu tentukan sama ada hendak tamat perang – Presiden Iran

September 26, 2026

Trump backs Hormuz alternative but his Iran war is blocking the route

September 26, 2026

Alleged defamatory comments against Home Minister: High Court orders govt. not to take coercive steps against CPI(M) member

September 25, 2026
Ammarzo Becoming the Fastest Growing Brand in Saudi Arabia

Ammarzo Becoming the Fastest Growing Brand in Saudi Arabia

September 25, 2026
Saturday, September 26, 2026
  • About us
  • Advertise with us
  • Submit Articles
  • Privacy Policy
  • Contact us
Asia Today
No Result
View All Result
Subscribe
  • Login
  • Eastern Asia
    • China
    • Japan
    • Mongolia
    • North Korea
    • South Korea
  • South-eastern Asia
    • Brunei
    • Cambodia
    • Indonesia
    • Laos
    • Malaysia
    • Myanmar
    • Philippines
    • Singapore
    • Thailand
    • Timor Leste
    • Vietnam
  • Southern Asia
    • Afghanistan
    • Bangladesh
    • Bhutan
    • India
    • Iran
    • Maldives
    • Nepal
    • Pakistan
    • Sri Lanka
  • Central Asia
    • Kazakhstan
    • Kyrgyzstan
    • Tajikistan
    • Turkmenistan
    • Uzbekistan
  • Western Asia
    • Armenia
    • Azerbaijan
    • Bahrain
    • Cyprus
    • Georgia
    • Iraq
    • Israel
    • Jordan
    • Kuwait
    • Lebanon
    • Oman
    • Qatar
    • Saudi Arabia
    • State of Palestine
    • Syria
    • Turkey
    • United Arab Emirates
    • Yemen
  • More News
    • Opinion
    • Politics
    • Business
    • Entertainment
    • Fashion
    • Food
    • Health
    • Lifestyle
    • Science
    • Tech
    • Sports
  • Eastern Asia
    • China
    • Japan
    • Mongolia
    • North Korea
    • South Korea
  • South-eastern Asia
    • Brunei
    • Cambodia
    • Indonesia
    • Laos
    • Malaysia
    • Myanmar
    • Philippines
    • Singapore
    • Thailand
    • Timor Leste
    • Vietnam
  • Southern Asia
    • Afghanistan
    • Bangladesh
    • Bhutan
    • India
    • Iran
    • Maldives
    • Nepal
    • Pakistan
    • Sri Lanka
  • Central Asia
    • Kazakhstan
    • Kyrgyzstan
    • Tajikistan
    • Turkmenistan
    • Uzbekistan
  • Western Asia
    • Armenia
    • Azerbaijan
    • Bahrain
    • Cyprus
    • Georgia
    • Iraq
    • Israel
    • Jordan
    • Kuwait
    • Lebanon
    • Oman
    • Qatar
    • Saudi Arabia
    • State of Palestine
    • Syria
    • Turkey
    • United Arab Emirates
    • Yemen
  • More News
    • Opinion
    • Politics
    • Business
    • Entertainment
    • Fashion
    • Food
    • Health
    • Lifestyle
    • Science
    • Tech
    • Sports
No Result
View All Result
Morning News
No Result
View All Result
Home Western Asia United Arab Emirates

Ransomware operators turn Ethereum into hidden command channel — Arabian Post

by Asia Today Team
August 6, 2026
in United Arab Emirates
Reading Time: 3 mins read
21 0
A A
0
Ransomware operators turn Ethereum into hidden command channel — Arabian Post
25
SHARES
307
VIEWS
Share on FacebookShare on Twitter

READ ALSO

A Global Player Across Two RMB100-Billion Aquatic Markets, as Honghu Lotus Root Ranks No. 1 in Antioxidant Content — Arabian Post

Binzhou Aerospace Exploration Center, New Landmark for Science, Cultural Tourism — Arabian Post


Ransomware operators are utilizing Ethereum good contracts to hide command-and-control addresses, giving malware a resilient technique to find attacker-controlled servers even after defenders block identified domains.

The approach has been linked to an affiliate of The Gents ransomware operation, which deployed a Node. js backdoor referred to as EtherRAT throughout intrusions focusing on Home windows networks. As a substitute of storing a hard and fast command server contained in the malware, EtherRAT reads a sensible contract on the Ethereum blockchain to acquire an energetic area.

The association permits operators to interchange compromised or blocked infrastructure with out rebuilding and redistributing the malware. They’ll replace information held by the good contract, directing contaminated computer systems in the direction of a unique server whereas retaining the identical blockchain handle within the implant.

Proof of the operation emerged from an uncovered server listing related to infrastructure beforehand linked to The Gents. The fabric supplied an in depth view of an intrusion toolkit used for persistent entry, credential theft, distant management and motion between techniques.

The affiliate created a privileged Home windows account named “support2” and established scheduled duties able to launching PowerShell instructions. These duties downloaded and executed malicious Microsoft Installer packages on distant machines, serving to the attackers unfold their instruments throughout the focused setting.

One installer deployed EtherRAT alongside Sliver shellcode and several other Go-based applications. Sliver is a command-and-control framework that may present operators with a further route into compromised networks. The Go binaries included reverse-shell capabilities, creating additional channels for issuing instructions and sustaining entry.

The toolkit additionally contained materials related to extracting credentials from the Native Safety Authority Subsystem Service, or LSASS. This Home windows course of shops delicate authentication info in reminiscence. Profitable entry can expose password hashes, tokens and different credentials that will allow attackers to impersonate customers or compromise area accounts.

Different elements had been designed to intervene with endpoint safety merchandise and set up encrypted tunnels from affected techniques. The mix signifies that EtherRAT was not getting used as an remoted backdoor. It shaped a part of a wider operation aimed toward gaining administrative management earlier than information theft and ransomware deployment.

Infrastructure evaluation linked the exercise to a number of web protocol addresses and internet hosting networks. Some servers uncovered open directories containing payloads, sufferer artefacts and operational information. Intently named installer packages discovered on separate techniques used the identical Ethereum good contract, strengthening the evaluation that they belonged to a standard marketing campaign.

The Gents operation has additionally been related to TukTuk, one other command-and-control framework noticed throughout ransomware intrusions. Attackers have mixed such frameworks with reputable remote-management software program, permitting malicious exercise to mix with instruments generally utilized by company help groups.

EtherRAT has appeared by way of a couple of supply route. Campaigns have distributed installers disguised as trusted administrative utilities, focusing on system directors, safety specialists and DevOps personnel who maintain elevated community privileges. Different exercise has used misleading verification prompts or software-download pages to influence customers to run malicious instructions.

As soon as put in, the backdoor can collect system and area info, examine operating processes and determine safety merchandise. It generates internet requests that resemble strange picture, stylesheet or icon downloads, utilizing diverse file extensions and question parameters to cut back the probability that routine visitors monitoring will flag a constant sample.

Using public blockchains for malware coordination is broader than a single ransomware group. Different legal operations have saved proxy addresses or malicious code in good contracts on Ethereum, Polygon and BNB Good Chain. State-linked attackers have additionally adopted blockchain-based supply strategies to make malicious infrastructure tougher to take away.

Blockchain data are distributed throughout many unbiased nodes, leaving no central server that defenders can seize to erase the saved info. Studying information from a contract may require no new blockchain transaction, limiting the seen monetary exercise that investigators may in any other case observe.

The good contract doesn’t essentially host the ultimate ransomware or backdoor. In EtherRAT infections, it features as a sturdy resolver that tells the implant the place to attach. The attacker-controlled server can then present instructions, further code or reconnaissance modules.

Defenders can nonetheless disrupt the chain by blocking recognized domains and web protocol addresses, eradicating scheduled duties, inspecting uncommon installer exercise and proscribing unauthorised PowerShell execution. Monitoring calls to public blockchain interfaces from gadgets that don’t have any enterprise want for them can even reveal suspicious behaviour.



Source link

Tags: ArabianchannelcommandEthereumHiddenoperatorsPostRansomwareTurn

Related Posts

United Arab Emirates

A Global Player Across Two RMB100-Billion Aquatic Markets, as Honghu Lotus Root Ranks No. 1 in Antioxidant Content — Arabian Post

September 25, 2026
United Arab Emirates

Binzhou Aerospace Exploration Center, New Landmark for Science, Cultural Tourism — Arabian Post

September 24, 2026
United Arab Emirates

Global Mayors Dialogue in Wuhan focuses on urban innovation and cooperation — Arabian Post

September 24, 2026
United Arab Emirates

Singapore-built AI oral examiner PSLEPrep analysed 12,459 answers in English and Chinese for its first Oral Practice Report. — Arabian Post

September 23, 2026
United Arab Emirates

Toblerone Launches Truffles with Biscoff® — Arabian Post

September 22, 2026
United Arab Emirates

Water disruptions push South African firms toward resilience — Arabian Post

September 22, 2026
Asia Today

Copyright © 2022 Asia Today.

Navigate Site

  • Disclaimer
  • Privacy Policy
  • Cookie Privacy Policy
  • DMCA
  • Terms and Conditions
  • Contact us

Follow Us

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Homepages
  • World
  • Eastern Asia
    • China
    • Japan
    • Mongolia
    • North Korea
    • South Korea
  • South-eastern Asia
    • Brunei
    • Cambodia
    • Indonesia
    • Laos
    • Malaysia
    • Myanmar
    • Philippines
    • Singapore
    • Thailand
    • Timor Leste
    • Vietnam
  • Southern Asia
    • Afghanistan
    • Sri Lanka
    • Bangladesh
    • Bhutan
    • India
    • Iran
    • Maldives
    • Nepal
    • Pakistan
    • Central Asia
    • Kazakhstan
    • Kyrgyzstan
    • Tajikistan
    • Turkmenistan
    • Uzbekistan
  • Western Asia
    • Armenia
    • Azerbaijan
    • Bahrain
    • Cyprus
    • Georgia
    • Iraq
    • Israel
    • Jordan
    • Kuwait
    • Lebanon
    • Oman
    • Qatar
    • Saudi Arabia
    • State of Palestine
    • Syria
    • Turkey
    • United Arab Emirates
    • Yemen
  • Opinion
  • Politics
  • Business
  • Entertainment
  • Fashion
  • Food
  • Health
  • Lifestyle
  • Science
  • Tech
  • Travel
  • Sports
  • About us
  • Advertise with us
  • Privacy Policy
  • Contact us
  • Support AsiaToday

Copyright © 2022 Asia Today.