← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware
An intrusion was observed in April 2026 where threat actors deployed EtherRAT malware through a malicious MSI installer disguised as a Sysinternals tool. The malware utilized Ethereum blockchain via EtherHiding for dynamic C2 configuration updates. Following reconnaissance activities, actors deployed TukTuk malware framework using DLL sideloading techniques with legitimate applications like Greenshot and SyncTrayzor. TukTuk established C2 channels through SaaS platforms including ClickHouse and Supabase, with backup channels via Ably, Dropbox, and GitHub Issues. The actors performed Kerberoasting, credential theft via Mimikatz and LSASS dumping, and deployed GoTo Resolve RMM tooling for lateral movement. Data exfiltration to Wasabi cloud storage was conducted using Rclone before deploying The Gentlemen ransomware domain-wide through a malicious GPO. The intrusion leveraged blockchain infrastructure, SaaS platforms, and decentralized services to evade traditional network defenses.
MITRE ATT&CK & Malware Families
Indicators of Compromise (6 / 45 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA1 | 114ec028a3fc4ed50056ee8166b0c39acff6ff03 | — | 2026-05-11 | |
| FileHash-SHA1 | 3d5ee8429ef00824c0351cba507dfeb92b54f83b | — | 2026-05-11 | |
| FileHash-SHA1 | aa9218994798ae31a19d3e7e39cfac2e2ee55840 | — | 2026-05-11 | |
| FileHash-SHA1 | b44c8084b88d31113ee51758740eb84c251bdae8 | — | 2026-05-11 | |
| FileHash-SHA1 | ba80d7b038758a129861e1e498e462cc3d68ae20 | — | 2026-05-11 | |
| FileHash-SHA1 | c98ee41f09ae079a5643626f57eb84f92205bb2b | — | 2026-05-11 |