Ransomware operators are now abusing Ethereum smart contracts as stealthy command”‘and”‘control resolvers, with a Gentlemen ransomware affiliate using the EtherRAT backdoor to pull rotating C2 domains directly from the blockchain instead of hardcoding them in the malware. The toolkit shows a clear progression: scheduled tasks that bootstrap PowerShell, privileged account creation (“support2” with Supp0rt2@2026!). LSASS […] The post Ransomware Hackers Are Hiding Malware Command Servers Inside Ethereum Smart Contracts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
First seen on gbhackers.com
Jump to article: gbhackers.com/ethereum-smart-contracts/
![]()

