
Just a few months ago, attackers used Ethereum to manage malware communications during an intrusion that ended with The Gentlemen ransomware being deployed. By updating configuration data stored on the blockchain, they could direct the malware to a new server without reinstalling it on the affected systems.
This technique, known as EtherHiding, allows attackers to store server addresses, configuration data, or malicious code on a public blockchain. When malware retrieves server addresses this way, blocking one destination may only interrupt communications until the operator supplies a replacement.
Blockchain infrastructure also supports victim communications after a compromise. DeadLock uses Polygon for its victim communication and data leak application, while Cry0 advertises blockchain-hosted negotiation sites.
This article explains how these approaches work, distinguishes observed activity from operator claims, and explains how organizations can reduce the risk of data theft and extortion.
How EtherHiding Works

EtherHiding’s address-retrieval mechanism depends on a smart contract: a program deployed on a blockchain that can store information and return it when queried. Malware or a victim-facing application can use that contract to find the server it needs to contact.
The process generally follows five steps:
- The attacker stores a server address. The operator places a command-and-control (C2) or proxy address in a smart contract. The malware or application contains the contract address needed to retrieve it.
- The software queries the contract. It contacts a blockchain remote procedure call (RPC) gateway and requests the data returned by a particular contract function.
- The contract returns the destination. A common RPC method, eth_call, reads contract data without creating a new blockchain transaction. This read operation requires no cryptocurrency wallet or transaction fee.
- The software connects to the server. It decodes the returned information where necessary, then contacts the destination to retrieve commands or relay communications.
- The attacker replaces the address. If the contract permits updates, the operator can change the destination. Software that queries the contract again can discover the replacement without being reinstalled.
The blockchain supplies the address, while a separate server handles the connection. Blocking that server can interrupt activity, but the software may reconnect elsewhere if it continues checking the contract.
The Gentlemen: Ethereum-Based C2 Before Encryption
In the intrusion involving The Gentlemen, a user executed a malicious MSI installer impersonating the Sysinternals RAMMap utility. The installer deployed EtherRAT, which queried Ethereum for its command-and-control configuration.
Initially, no active C2 destination was available. The attacker later updated the configuration to point to a TryCloudflare tunnel, enabling communications with the installed malware.
The attackers then stole credentials, installed remote management tools, and moved across the network. They used Rclone to transfer sensitive data to Wasabi storage before deploying The Gentlemen ransomware through a malicious Group Policy Object.
Separate tooling associated with an affiliate of The Gentlemen shows how EtherRAT was deployed across Windows systems. The recovered script below creates remote scheduled tasks that download and silently install an MSI package.

Figure 1: EtherRAT deployment script (credentials redacted).
The EtherRAT sample examined alongside this tooling checked its Ethereum contract approximately every five minutes for a new C2 address. It contained seven public RPC endpoints, providing alternative gateways to the same blockchain.
https://mainnet.gateway.tenderly.co
https://rpc.flashbots.net/fast
https://rpc.mevblocker.io
https://eth-mainnet.public.blastapi.io
https://ethereum-rpc.publicnode.com
https://eth.drpc.org
https://eth.merkle.io
The contract’s update history revealed five C2 domains used between April and July 2026. The operator could change destinations, but those updates also left a record investigators could reconstruct. These findings establish EtherRAT use in affiliate activity, without showing that every affiliate of The Gentlemen uses it.
DeadLock: Polygon-Based Victim Communications
The Gentlemen case used blockchain lookups to support access during an intrusion. DeadLock applies a similar mechanism to victim communications after encryption.
DeadLock drops an HTML application that victims can open in a browser. The application retrieves a proxy address from a Polygon smart contract, then uses that proxy to relay messages through the Session network. Fallback RPC gateways provide alternative routes for retrieving the address.
Its Chat tab presents login and password fields and a Connect button.

Figure 2: DeadLock’s chat login.
The application also includes a Blog tab that displays the operators’ claims of stolen data. A second Polygon contract supplies post content and attachment links, while the leaked files themselves are held in Wasabi storage.

Figure 3: DeadLock’s leak blog (victim details redacted).
These functions give the blockchain two roles: distributing the messaging proxy’s address and supplying content for the leak blog. The proxy and file storage remain separate services that can be disrupted.
DeadLock’s implementation supports extortion after compromise. It does not establish that the ransomware encryptor was delivered through EtherHiding.
Cry0: Claims About Blockchain-Hosted Negotiations
Cry0 advertises blockchain infrastructure for victim negotiations, but its claimed approach differs from the address lookups used by EtherRAT and DeadLock.
As part of its ransomware-as-a-service (RaaS) offering, Cry0 claims to host negotiation sites on Internet Computer Protocol (ICP) through decentralized smart contracts. This would place the victim-facing service itself on blockchain infrastructure.
In the forum post below, dated December 8, 2025, Cry0 advertises blockchain-hosted landing pages and claims they resulted in higher payment conversion rates.

Figure 4: Cry0’s blockchain infrastructure claims (unverified).
Stopping Data Theft Before Encryption
Across these examples, blockchain infrastructure supports different stages of an operation. EtherRAT helped attackers establish communications before The Gentlemen ransomware was deployed. DeadLock’s application and Cry0’s advertised portals support the negotiations that follow a compromise.
Containing an intrusion like this requires removing the implant and securing compromised accounts and remote access tools. Blocking a C2 destination alone would leave the malware able to retrieve a replacement address.
Security teams can look for unexpected remote management software, privileged account changes, and outbound file transfers to uncover an intrusion before encryption begins. The attackers’ use of Rclone to send files to Wasabi shows why transfers to cloud storage should be checked against approved business activity.
Organizations can also use BlackFog’s anti data exfiltration (ADX) technology to prevent unauthorized data from leaving devices through real-time network filtering. Blocking those transfers stops attackers from acquiring the files they would use to threaten disclosure, even if they can keep replacing their C2 infrastructure.
Share This Story, Choose Your Platform!
Related Posts
EtherHiding: How Ransomware Groups Use the Blockchain to Resist Takedowns
Learn how EtherHiding works and how The Gentlemen, DeadLock, and Cry0 use blockchain infrastructure to update malware server addresses, maintain victim communications, and support ransom negotiations and data extortion.
Gunra Ransomware: Why Stopping Data Exfiltration Matters Before Encryption Begins
Gunra ransomware steals critical data before encryption. Learn how to stop this emerging double extortion threat with anti data exfiltration.
Claude Coding Jailbreak: Latest Risks And Enterprise Impact
Claude coding jailbreaks: recent research, how enterprises can reduce artificial intelligence (AI) security risks with better monitoring and governance.
What Are The Advantages Of Using AI In Intrusion Detection?
Explore the advantages of AI in intrusion detection, from faster analysis and greater scale to identifying previously unseen attack patterns.
How Can Cybersecurity Professionals Defend Against Threats Posed By Malicious AI Tools?
Learn how cybersecurity professionals can defend against malicious AI tools with AI-specific monitoring, least-privilege access and outbound visibility.
Are There Any Government Policies On Using AI For Cybersecurity?
Learn how the EU AI Act and US NIST frameworks address the use of AI in cybersecurity and what their different approaches mean for businesses.





