Remote Scheduled Tasks Spread EtherRAT Across Compromised Windows Domain

EtherRAT has surfaced in a Windows domain intrusion tied to an affiliate of the Gentlemen ransomware operation. The campaign shows how a single foothold can become a network-wide problem when attackers gain privileged access. The operators used remote scheduled tasks to push malicious installer packages to other systems. Those installers deployed EtherRAT, a remote access […]

This article has been indexed from Cyber Security News

Read the original article: