An exposed directory on 193.233.202[. ]17 has revealed a detailed intrusion toolkit linked to suspected affiliate of The Gentlemen ransomware operation. Recovered files indicate an operator preparing for long-term access to Windows networks, credential theft, disabling security products, moving across domains, and deploying multiple command-and-control (C2) channels.

Directory contained 82 files totaling approximately 145 MB. Researchers recovered 37 Windows executables, 22 PowerShell scripts, nine batch files, six scheduled-task XML files, an EtherRAT MSI installer, Sliver payloads, Go-based reverse shells, Chisel, Ligolo-ng, Mimikatz, and several Potato-family privilege-escalation tools. Hunt.io platform exposes an open directory at 193.233.202[. ]17 (Source: Hunt.io) The Huntress previously identified 193.233.202[.

]17 and 77.110.122[. ]137 as proxy endpoints linked to The Gentlemen’s defense-evasion activities.

Although this campaign was not officially attributed, the shared Ethereum smart contract, similar MSI naming, and overlapping infrastructure suggest a potential connection to the same cluster. The Gentlemen Affiliate Deployed EtherRAT The perpetrator extensively utilized Windows scheduled tasks to remotely execute PowerShell scripts and deploy payloads on internal systems. It also stopped and disabled multiple ESET services, exported the SAM, SYSTEM, and SECURITY registry hives, and uploaded them to attacker-controlled infrastructure.

After installation, it creates files in %LOCALAPPDATA%\MicrosoftSltt, downloads Node.js if necessary, decrypts its JavaScript backdoor, and establishes persistence using the WindowsHost Registry Run key. Researchers re-created five historical EtherRAT domains: publisherresolution[. ]com, resumeacceptable[. ]com, simultaneouslypower[.

]com, wiselystarting[. ]com, and itemrange[. ]com.