EtherRAT, TukTuk Chain Delivers Gentlemen Ransomware
An intrusion using EtherRAT and the AI-generated TukTuk backdoor abused Ethereum, Arweave, and SaaS platforms for C2 before deploying The Gentlemen ransomware domain-wide.
The DFIR Report details an April intrusion linked to a broader EtherRAT campaign first documented by Sysdig (exploiting CVE-2025-55182/React2Shell on Linux) and later observed on Windows by Atos. Initial access came from a malicious MSI masquerading as the Sysinternals RAMMap utility, which deployed an EtherRAT variant using "EtherHiding" — querying Ethereum smart contracts via 1rpc.io — to dynamically fetch C2 configuration, including decoy domains meant to confuse defenders and later pivoting to a TryCloudflare tunnel once the actor activated live infrastructure.
The intrusion escalated with deployment of TukTuk, a newly identified, reportedly AI-generated malware framework delivered via DLL sideloading disguised as legitimate tools (Greenshot, SyncTrayzor, DocFX, Cake). TukTuk established C2 through SaaS platforms including ClickHouse and Supabase, with fallback channels over Ably, Dropbox, GitHub Issues, and an Arweave-based dead-drop resolver capable of retrieving encrypted multi-transport credential blobs. The actor then conducted Kerberoasting, LSASS/NTDS credential dumping, and broad AD reconnaissance, before using compromised service accounts to deploy the GoTo Resolve RMM tool laterally across servers and domain controllers.
Over several days the actor moved via RDP, SMB, WinRM, and NetExec, dumped credentials with Mimikatz, and exfiltrated large volumes of data using Rclone to Wasabi cloud storage. The intrusion culminated in domain-wide deployment of The Gentlemen ransomware via a malicious Group Policy Object executing staged binaries from SYSVOL/NETLOGON, preceded by Defender tampering, shadow copy deletion, and log clearing. The campaign's reliance on decentralized blockchain infrastructure (Ethereum, Arweave) alongside legitimate SaaS and RMM platforms provides notable resilience against conventional network-based defenses; Supabase, ClickHouse, and GoTo assisted in taking down related infrastructure.
Mentioned in this report
Source reporting: https://thedfirreport.com/2026/05/11/flash-alert-etherrat-and-tuktuk-c2-end-in-the-gentleman-ransomware
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free