Menu

Post image 1
Post image 2
1 / 2
0

Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware

DEV Community·Mark0·21 days ago
#VrgVEdUg
Reading 0:00
15s threshold

In April, a sophisticated cyber intrusion was identified involving the deployment of EtherRAT via a malicious MSI installer masquerading as a Sysinternals tool. This campaign utilized the Ethereum blockchain through EtherHiding to dynamically update command-and-control (C2) configurations, effectively bypassing traditional network defenses. The attackers further deployed TukTuk, an AI-generated malware framework that leverages an array of SaaS platforms including ClickHouse, Supabase, and Arweave for resilient communication and dead-drop resolution. Following initial access, the threat actor engaged in extensive lateral movement using GoTo Resolve RMM and tools like NetExec. Sensitive data was exfiltrated to Wasabi cloud storage using Rclone before the intrusion culminated in the environment-wide deployment of The Gentleman ransomware via Group Policy Objects (GPO).…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More