Back to Blog
Malicious Infrastructure Ransomware: EtherRAT Distributed via Blockchain-Enabled C2 (June 2026)
ransomware

Malicious Infrastructure Ransomware: EtherRAT Distributed via Blockchain-Enabled C2 (June 2026)

breachwire TeamJun 16, 20265 min read

Malicious Infrastructure: What Happened

A globally distributed malicious infrastructure was identified delivering EtherRAT malware, phishing pages, and additional malicious payloads through publicly accessible websites and open directories. The infrastructure utilized MSI installers, PowerShell scripts, and JavaScript to propagate EtherRAT—a Node.js-based remote access trojan that retrieves its command and control (C2) server via the Ethereum blockchain. The campaign enabled attackers to gain full control over infected endpoints, with the impact confirmed across multiple regions. The infrastructure also hosted phishing pages, broadening the threat surface and increasing the likelihood of credential theft and secondary infections.

Attack Vector & Technical Detail

Attackers leveraged open directories and public websites to distribute malicious files, including v1.msi, v2.ps1, v9.msi, KmPuGimn.cmd, and cDQMlQAru0.xml. These files served as initial infection vectors, often delivered through deceptive links or phishing emails. EtherRAT’s unique use of the Ethereum blockchain—specifically, querying contract 0x88ea8d0bc4146f0a018e989df3fd089ac48f9a58 with function selector 0x7d434425 and argument 0xf6a772e163e64b07f658946f863b5d457d88f9f0—enabled dynamic retrieval of C2 infrastructure, bypassing traditional domain-based takedowns. MITRE tactics observed include Initial Access (TA0001), Execution (TA0002), Defense Evasion (TA0005), Credential Access (TA0006), and Command and Control (TA0011). Notably, the use of mainnet.gateway.tenderly.co as a blockchain gateway further complicated detection and response efforts.

Confirmed Impact

The confirmed impact includes remote code execution, file and registry modification, data exfiltration, and persistent access to compromised systems. The campaign’s global reach exposes organizations in multiple jurisdictions to potential data privacy violations and regulatory scrutiny, particularly where sensitive or regulated data was accessed or exfiltrated. The resilience of EtherRAT’s C2 mechanism, facilitated by blockchain technology, significantly increases the difficulty of mitigation and takedown, prolonging attacker dwell time and amplifying operational risk.

What This Means for Your Organization

Organizations should recognize the evolving threat landscape, where attackers increasingly leverage decentralized technologies such as blockchain to evade detection and takedown. The use of open directories and public web infrastructure for malware distribution underscores the need for robust web filtering, endpoint monitoring, and user awareness training. Defenders must adapt detection strategies to include monitoring for blockchain-based C2 communications and unusual script execution patterns. Proactive threat hunting for known IOCs, such as v1.msi and mainnet.gateway.tenderly.co, is essential to identify and contain infections early.

Detection & Response

  • Immediate: Block access to known malicious files and domains, including v1.msi, v2.ps1, v9.msi, and mainnet.gateway.tenderly.co, across all endpoints and network egress points.
  • Hunt: Search for execution or presence of IOCs such as KmPuGimn.cmd, cDQMlQAru0.xml, and blockchain contract interactions with 0x88ea8d0bc4146f0a018e989df3fd089ac48f9a58.
  • Patch: N/A (no CVEs directly involved in this campaign).

Source: https://www.malwarebytes.com/blog/threat-intel/2026/06/inside-a-malicious-infrastructure-delivering-etherrat-phishing-pages-and-malicious-software

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: