Tuesday, September 8, 2026

The Gentlemen Ransomware Hackers Use TukTuk C2 to Steal Credentials and Disable EDR Security

The Gentlemen ransomware operation has been linked to a previously undocumented, cross-platform command-and-control framework named TukTuk, alongside EDR-disabling tooling, DLL sideloading research, and datasets apparently stolen from technology and healthcare organizations.

Analysis of a Finland-hosted server identified what researchers assess as the complete TukTuk development project, providing an unusually detailed view into the group’s post-compromise capabilities.

The server, hosted at IP address 65.109.70.162 on Hetzner Online infrastructure, contained attack tools, research materials, and exfiltrated data in the same environment.

The collection included tuktuk-v2.0_10.zipTukTuk.exe, a Greenshot DLL sideloading package, EDR-killer components, vulnerable-driver testing resources, 224 Jira tickets, and infrastructure credentials tied to a global healthcare firm.

The archive contained four core TukTuk components: a Windows agent, Linux agent, backend service, and Electron/Node.js-based operator panel.

The recovered code indicates that the framework can collect host information, receive commands, manage files, capture screenshots, and support interactive shell activity on compromised endpoints.

The panel’s functionality goes beyond basic remote access. Its interface reportedly includes server and agent management, process control, screenshot galleries, credential listings, file upload functions, predefined command shortcuts, and arbitrary command execution.

A “Cred Prompt” feature can display a spoofed Windows Security dialogue and capture credentials entered by the victim.

The earlier campaign began with a malicious MSI installer impersonating Microsoft Sysinternals RAMMap, then used cloud and SaaS-backed communications, including ClickHouse, Supabase, Dropbox, GitHub Issues, Slack, Ably, and Arweave-based dead-drop resolution.

The presence of separate Windows and Linux agents suggests TukTuk was designed for mixed enterprise environments, rather than as a single-platform implant.

Its backend processes agent connections based on listeners configured through the panel, handling task distribution, execution results, and host status.

Researchers also recovered a DLL sideloading set consisting of a legitimate Greenshot.exe executable and a malicious log4net.dll.

 TukTuk C2 dashboard showing hostname DESKTOP-22EVPBQ (Source : Oasis).
 TukTuk C2 dashboard showing hostname DESKTOP-22EVPBQ (Source : Oasis).

When Greenshot starts, it loads the attacker-controlled DLL from its local directory, launching the TukTuk agent under the cover of a trusted application.

Oasis Researchers said that, capability aligns with prior reporting on a The Gentlemen intrusion in which attackers deployed EtherRAT followed by TukTuk before rolling out ransomware across the victim environment.

TukTuk C2 Framework

Static analysis of the malicious log4net.dll reportedly identified TukTuk-related code, server addresses, token data, and configuration elements associated with Slack, GitHub, and Dropbox.

VirusTotal detections for TukTuk.exe, flagged as malicious by 2 of 68 vendors (Source : Oasis).
VirusTotal detections for TukTuk.exe, flagged as malicious by 2 of 68 vendors (Source : Oasis).

The sample has been detected by 17 of 72 antivirus engines, while TukTuk.exe was flagged by only two of 68 vendors at the time of analysis an illustration of how custom or emerging tooling can retain a low detection footprint.

The server also held sideloading research involving ProcMon, Slack, and Postman, suggesting operators were testing multiple legitimate applications as potential loaders.

Earlier public reporting similarly observed trojanized utilities such as Greenshot, SyncTrayzor, DocFX, and Cake within the broader intrusion chain.

The strongest attribution artifact was eb.sys, whose SHA-256 hash matched a known GentleKiller sample associated with The Gentlemen.

GentleKiller is an EDR-killer toolkit used to interfere with endpoint protection products by abusing kernel drivers.

The analyzed server also contained credential and infrastructure-related information associated with a global healthcare company’s Infrastructure-as-Code (IaC) Platform.

The recovered materials were organized as four lessons covering EDR-killer development, BYOVD Bring Your Own Vulnerable Driver testing, vulnerable-driver hunting, and kernel-level research.

Security assessment report for the healthcare organization's IaC platform, covering AWS, Azure AD, Bitbucket, and infrastructure configuration environments  (Source : Oasis).
Security assessment report for the healthcare organization’s IaC platform, covering AWS, Azure AD, Bitbucket, and infrastructure configuration environments (Source : Oasis).

Files associated with EDRKiller, WarsawKiller, UnknownKiller, and wsftprm.sys indicate an operational focus on loading drivers, accessing protected processes, and terminating security tooling.

Notably, one lesson compared automatic recovery behavior among EDR products after process termination.

Such testing can help ransomware operators identify the short window between disabling an endpoint product and its self-recovery, enabling follow-on actions such as credential theft, lateral movement, data staging, or encryption.

The server also contained 224 Jira tickets and eight attachments assessed as exfiltrated from a global technology company’s Jira environment.

The material reportedly included support records, credentials, infrastructure details, vulnerability information, technical attachments, penetration-testing reports, and confidential proof-of-concept code.

Some records were connected to U.S. defense organizations, contractors, and aerospace entities, exposing potentially sensitive details such as host and system identifiers, network information, authentication problems, support logs.

Separately, analysts found credential and infrastructure data associated with a global healthcare company’s Infrastructure-as-Code platform.

The material included AWS access information, production database credentials, Azure AD and Bitbucket details, cloud-storage references, VPC endpoint data, certificates, and infrastructure-configuration artifacts.

The combination of credential harvesting, EDR neutralization, reusable malware development, and data theft shows that The Gentlemen is operating as more than an encryption-focused ransomware actor.

The group appears to maintain a technical ecosystem for initial access support, stealth, credential collection, persistence, cross-platform remote control, and high-value data exfiltration before ransomware deployment.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Related Articles

Recent News