By |Last Updated: September 29th, 2026|7 min read|Categories: Data Exfiltration, Breach, Exploits|

Contents

Just a few months ago, attackers used Ethereum to manage malware communications during an intrusion that ended with The Gentlemen ransomware being deployed. By updating configuration data stored on the blockchain, they could direct the malware to a new server without reinstalling it on the affected systems.

This technique, known as EtherHiding, allows attackers to store server addresses, configuration data, or malicious code on a public blockchain. When malware retrieves server addresses this way, blocking one destination may only interrupt communications until the operator supplies a replacement.

Blockchain infrastructure also supports victim communications after a compromise. DeadLock uses Polygon for its victim communication and data leak application, while Cry0 advertises blockchain-hosted negotiation sites.

This article explains how these approaches work, distinguishes observed activity from operator claims, and explains how organizations can reduce the risk of data theft and extortion.

How EtherHiding Works

EtherHiding’s address-retrieval mechanism depends on a smart contract: a program deployed on a blockchain that can store information and return it when queried. Malware or a victim-facing application can use that contract to find the server it needs to contact.

The process generally follows five steps:

  1. The attacker stores a server address. The operator places a command-and-control (C2) or proxy address in a smart contract. The malware or application contains the contract address needed to retrieve it.
  2. The software queries the contract. It contacts a blockchain remote procedure call (RPC) gateway and requests the data returned by a particular contract function.
  3. The contract returns the destination. A common RPC method, eth_call, reads contract data without creating a new blockchain transaction. This read operation requires no cryptocurrency wallet or transaction fee.
  4. The software connects to the server. It decodes the returned information where necessary, then contacts the destination to retrieve commands or relay communications.
  5. The attacker replaces the address. If the contract permits updates, the operator can change the destination. Software that queries the contract again can discover the replacement without being reinstalled.

The blockchain supplies the address, while a separate server handles the connection. Blocking that server can interrupt activity, but the software may reconnect elsewhere if it continues checking the contract.

The Gentlemen: Ethereum-Based C2 Before Encryption

In the intrusion involving The Gentlemen, a user executed a malicious MSI installer impersonating the Sysinternals RAMMap utility. The installer deployed EtherRAT, which queried Ethereum for its command-and-control configuration.

Initially, no active C2 destination was available. The attacker later updated the configuration to point to a TryCloudflare tunnel, enabling communications with the installed malware.

The attackers then stole credentials, installed remote management tools, and moved across the network. They used Rclone to transfer sensitive data to Wasabi storage before deploying The Gentlemen ransomware through a malicious Group Policy Object.

Separate tooling associated with an affiliate of The Gentlemen shows how EtherRAT was deployed across Windows systems. The recovered script below creates remote scheduled tasks that download and silently install an MSI package.

Figure 1: EtherRAT deployment script (credentials redacted).

The EtherRAT sample examined alongside this tooling checked its Ethereum contract approximately every five minutes for a new C2 address. It contained seven public RPC endpoints, providing alternative gateways to the same blockchain.

https://mainnet.gateway.tenderly.co

https://rpc.flashbots.net/fast

https://rpc.mevblocker.io

https://eth-mainnet.public.blastapi.io

https://ethereum-rpc.publicnode.com

https://eth.drpc.org

https://eth.merkle.io

The contract’s update history revealed five C2 domains used between April and July 2026. The operator could change destinations, but those updates also left a record investigators could reconstruct. These findings establish EtherRAT use in affiliate activity, without showing that every affiliate of The Gentlemen uses it.

DeadLock: Polygon-Based Victim Communications

The Gentlemen case used blockchain lookups to support access during an intrusion. DeadLock applies a similar mechanism to victim communications after encryption.

DeadLock drops an HTML application that victims can open in a browser. The application retrieves a proxy address from a Polygon smart contract, then uses that proxy to relay messages through the Session network. Fallback RPC gateways provide alternative routes for retrieving the address.

Its Chat tab presents login and password fields and a Connect button.

Figure 2: DeadLock’s chat login.

The application also includes a Blog tab that displays the operators’ claims of stolen data. A second Polygon contract supplies post content and attachment links, while the leaked files themselves are held in Wasabi storage.

Figure 3: DeadLock’s leak blog (victim details redacted).

These functions give the blockchain two roles: distributing the messaging proxy’s address and supplying content for the leak blog. The proxy and file storage remain separate services that can be disrupted.

DeadLock’s implementation supports extortion after compromise. It does not establish that the ransomware encryptor was delivered through EtherHiding.

Cry0: Claims About Blockchain-Hosted Negotiations

Cry0 advertises blockchain infrastructure for victim negotiations, but its claimed approach differs from the address lookups used by EtherRAT and DeadLock.

As part of its ransomware-as-a-service (RaaS) offering, Cry0 claims to host negotiation sites on Internet Computer Protocol (ICP) through decentralized smart contracts. This would place the victim-facing service itself on blockchain infrastructure.

In the forum post below, dated December 8, 2025, Cry0 advertises blockchain-hosted landing pages and claims they resulted in higher payment conversion rates.

Figure 4: Cry0’s blockchain infrastructure claims (unverified).

Stopping Data Theft Before Encryption

Across these examples, blockchain infrastructure supports different stages of an operation. EtherRAT helped attackers establish communications before The Gentlemen ransomware was deployed. DeadLock’s application and Cry0’s advertised portals support the negotiations that follow a compromise.

Containing an intrusion like this requires removing the implant and securing compromised accounts and remote access tools. Blocking a C2 destination alone would leave the malware able to retrieve a replacement address.

Security teams can look for unexpected remote management software, privileged account changes, and outbound file transfers to uncover an intrusion before encryption begins. The attackers’ use of Rclone to send files to Wasabi shows why transfers to cloud storage should be checked against approved business activity.

Organizations can also use BlackFog’s anti data exfiltration (ADX) technology to prevent unauthorized data from leaving devices through real-time network filtering. Blocking those transfers stops attackers from acquiring the files they would use to threaten disclosure, even if they can keep replacing their C2 infrastructure.

About BlackFog

BlackFog is the category-defining vendor in anti data exfiltration (ADX). Founded in 2015, the company invented ADX on the thesis that the endpoint is the only control point capable of stopping data from leaving an organization, an architectural bet that has now been validated across three exfiltration vectors: ransomware, shadow AI, and autonomous AI agents. BlackFog’s endpoint-native platform protects more than 500 enterprises, government agencies, and critical infrastructure operators worldwide. The company is the publisher of the annual State of Ransomware report and the BlackFog/Sapio Shadow AI Research, the most-cited primary research in the category. BlackFog’s recognition includes the teiss Awards 2026, the AI Excellence Award 2026, the Cybersecurity Excellence Awards 2026, and the Cybersecurity Breakthrough Award. Headquartered in San Francisco with international operations in London and Belfast. Learn more at blackfog.com.

Share This Story, Choose Your Platform!

Related Posts