Menu

Post image 1
Post image 2
1 / 2
0

Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware

DEV Community·Mark0·19 days ago
#gvuoOaXn
Reading 0:00
15s threshold

This technical analysis details a multi-stage intrusion involving EtherRAT and the AI-generated TukTuk malware framework, culminating in a domain-wide deployment of The Gentleman ransomware. The attack began with a malicious MSI installer masquerading as a Sysinternals RAMMap utility, which deployed an EtherRAT variant using the Ethereum blockchain for dynamic C2 configuration. The threat actors utilized a sophisticated array of decentralized infrastructure, including EtherHiding and Arweave dead-drop resolvers, alongside legitimate SaaS platforms like ClickHouse and Supabase to maintain resilient communication channels. Once persistence was established, the actors engaged in hands-on-keyboard activity, including Kerberoasting, LSASS dumping, and lateral movement via GoTo Resolve and NetExec. After exfiltrating sensitive data to Wasabi cloud storage using Rclone, the intrusion concluded with the execution of The Gentleman ransomware.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More