PULSE NAME
Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware
WHITE AlienVault 2026-05-11 Modified: 2026-05-11
45
IOCs
MEDIUM VOLUME
An intrusion was observed in April 2026 where threat actors deployed EtherRAT malware through a malicious MSI installer disguised as a Sysinternals tool. The malware utilized Ethereum blockchain via EtherHiding for dynamic C2 configuration updates. Following reconnaissance activities, actors deployed TukTuk malware framework using DLL sideloading techniques with legitimate applications like Greenshot and SyncTrayzor. TukTuk established C2 channels through SaaS platforms including ClickHouse and Supabase, with backup channels via Ably, Dropbox, and GitHub Issues. The actors performed Kerberoasting, credential theft via Mimikatz and LSASS dumping, and deployed GoTo Resolve RMM tooling for lateral movement. Data exfiltration to Wasabi cloud storage was conducted using Rclone before deploying The Gentlemen ransomware domain-wide through a malicious GPO. The intrusion leveraged blockchain infrastructure, SaaS platforms, and decentralized services to evade traditional network defenses.
Indicators of Compromise (6 / 45 total)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 73ce2438d4ed475e03727b7b000d2794 2026-05-11
FileHash-MD5 77fbe265fd65c7f7b6d323fb6de6a4fd 2026-05-11
FileHash-MD5 b188fbc6ff5557767e73e4c883a553a3 2026-05-11
FileHash-MD5 b2d51212744f404714fd909e87254d98 2026-05-11
FileHash-MD5 c92cf9a1af5b1fe25cdcb8771ce52be4 2026-05-11
FileHash-MD5 f985b8d6d635c266fc4779dad77aa75c 2026-05-11