Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware

https://workshop-lighting-protective-customs.trycloudflare.com

TLP:CLEAR
Active

URL

Description

An intrusion was observed in April 2026 where threat actors deployed EtherRAT malware through a malicious MSI installer disguised as a Sysinternals tool. The malware utilized Ethereum blockchain via EtherHiding for dynamic C2 configuration updates. Following reconnaissance activities, actors deployed TukTuk malware framework using DLL sideloading techniques with legitimate applications like Greenshot and SyncTrayzor. TukTuk established C2 channels through SaaS platforms including ClickHouse and Supabase, with backup channels via Ably, Dropbox, and GitHub Issues. The actors performed Kerberoasting, credential theft via Mimikatz and LSASS dumping, and deployed GoTo Resolve RMM tooling for lateral movement. Data exfiltration to Wasabi cloud storage was conducted using Rclone before deploying The Gentlemen ransomware domain-wide through a malicious GPO. The intrusion leveraged blockchain infrastructure, SaaS platforms, and decentralized services to evade traditional network defenses.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware
Pattern Type
STIX
Confidence
75%
Valid From
May 14, 2026 23:09
Total Sightings
0
Added
May 14, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of https://workshop-lighting-protective-customs.trycloudflare.com

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.