EtherRAT has surfaced in a Windows domain intrusion tied to an affiliate of the Gentlemen ransomware operation. The campaign shows how a single foothold can become a network-wide problem when attackers gain privileged access. The operators used remote scheduled tasks to push malicious installer packages to other systems. Those installers deployed EtherRAT, a remote access tool built around Node.js that can receive instructions, steal access, and keep running after the initial compromise. Recent reporting on EtherRAT blockchain hiding techniques shows why this design can make tracking its infrastructure harder. Analysts at Hunt.io identified the activity after finding an exposed directory on a server used during the...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!