PULSE NAME
Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware
WHITE AlienVault 2026-05-11 Modified: 2026-05-11
45
IOCs
MEDIUM VOLUME
An intrusion was observed in April 2026 where threat actors deployed EtherRAT malware through a malicious MSI installer disguised as a Sysinternals tool. The malware utilized Ethereum blockchain via EtherHiding for dynamic C2 configuration updates. Following reconnaissance activities, actors deployed TukTuk malware framework using DLL sideloading techniques with legitimate applications like Greenshot and SyncTrayzor. TukTuk established C2 channels through SaaS platforms including ClickHouse and Supabase, with backup channels via Ably, Dropbox, and GitHub Issues. The actors performed Kerberoasting, credential theft via Mimikatz and LSASS dumping, and deployed GoTo Resolve RMM tooling for lateral movement. Data exfiltration to Wasabi cloud storage was conducted using Rclone before deploying The Gentlemen ransomware domain-wide through a malicious GPO. The intrusion leveraged blockchain infrastructure, SaaS platforms, and decentralized services to evade traditional network defenses.
Indicators of Compromise (6 / 45 total)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 114ec028a3fc4ed50056ee8166b0c39acff6ff03 2026-05-11
FileHash-SHA1 3d5ee8429ef00824c0351cba507dfeb92b54f83b 2026-05-11
FileHash-SHA1 aa9218994798ae31a19d3e7e39cfac2e2ee55840 2026-05-11
FileHash-SHA1 b44c8084b88d31113ee51758740eb84c251bdae8 2026-05-11
FileHash-SHA1 ba80d7b038758a129861e1e498e462cc3d68ae20 2026-05-11
FileHash-SHA1 c98ee41f09ae079a5643626f57eb84f92205bb2b 2026-05-11