logo

Ransomware Hackers Use New TukTuk Malware to Steal Credentials and Disable Security Tools

ID: f96c172e-263e-5c6f-9487-e4083f3de2f6

STIX ID: report--f96c172e-263e-5c6f-9487-e4083f3de2f6

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-09-02

Date Updated: 2026-09-16

Author: Tushar Subhra Dutta

...
...

Oasis Security recovered a previously undocumented remote-control framework named TukTuk—Windows and Linux agents, backend, and operator panel—linked to the Gentlemen ransomware ecosystem; the toolkit enables credential theft via fake Windows security prompts, remote surveillance (screenshots, commands), and includes materials for disabling EDR using vulnerable drivers. The server contained malicious DLL sideloading artifacts, EDR-killer tools/drivers, and evidence of exfiltrated Jira tickets and cloud credentials from large organizations; researchers published IoCs and recommended rotating credentials, blocking indicators, isolating hosts, and hunting across Windows and Linux environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.