The Gentlemen Ransomware Hackers Use TukTuk C2 to Steal Credentials and Disable EDR Security
ID: a41b1c03-81cd-5ae8-87f3-150e30f47172
STIX ID: report--a41b1c03-81cd-5ae8-87f3-150e30f47172
Feed Name: GBHackers
Oasis researchers recovered a Finland-hosted server linked to The Gentlemen ransomware group containing the complete TukTuk C2 development project (Windows and Linux agents, backend, and operator panel), EDR-killer tooling, DLL sideloading packages (e.g., trojanized Greenshot with malicious log4net.dll), vulnerable-driver research, and exfiltrated data and credentials from global technology and healthcare firms; the framework supports host recon, credential capture (spoofed Windows prompt), file management, interactive shells, and mixed cloud/SaaS command channels, indicating a sophisticated, cross-platform ransomware ecosystem used for initial access, stealth, credential theft, and data staging prior to encryption.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
