Ransomware Hackers Use New TukTuk Malware to Steal Credentials and Disable Security Tools
ID: f96c172e-263e-5c6f-9487-e4083f3de2f6
STIX ID: report--f96c172e-263e-5c6f-9487-e4083f3de2f6
Feed Name: cybersecurityNews.com
Oasis Security recovered a previously undocumented remote-control framework named TukTuk—Windows and Linux agents, backend, and operator panel—linked to the Gentlemen ransomware ecosystem; the toolkit enables credential theft via fake Windows security prompts, remote surveillance (screenshots, commands), and includes materials for disabling EDR using vulnerable drivers. The server contained malicious DLL sideloading artifacts, EDR-killer tools/drivers, and evidence of exfiltrated Jira tickets and cloud credentials from large organizations; researchers published IoCs and recommended rotating credentials, blocking indicators, isolating hosts, and hunting across Windows and Linux environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
