Newly Discovered TukTuk C2 Framework Linked to The Gentlemen Ransomware Group
Threat intelligence researchers uncovered a command-and-control (C2) server tied to the ransomware group The Gentlemen, revealing a previously undocumented framework called TukTuk, tools to disable endpoint security, and stolen corporate data from two global companies.
The server, hosted by Hetzner Online in Finland (IP: 65.109.70.162), contained the full TukTuk v2.0 project, including Windows and Linux agents, a backend server, and an operator control panel. The framework enables attackers to monitor compromised devices, execute commands, manage files, capture screenshots, and harvest credentials via a fake Windows Security prompt.
Key findings include:
- Cross-platform capabilities: The Windows agent (C#) and Linux agent demonstrate TukTuk’s versatility beyond Windows-only attacks.
- DLL sideloading techniques: A malicious log4net.dll disguised as part of the legitimate Greenshot application was found, along with research on sideloading opportunities in ProcMon, Slack, and Postman.
- EDR-killing tools: The server hosted materials on BYOVD (Bring Your Own Vulnerable Driver) techniques, including files like EDRKiller, WarsawKiller, and an unidentified driver still lacking a CVE.
- Stolen data: 224 Jira tickets and eight attachments from a global tech company were recovered, containing infrastructure details, credentials, and sensitive information related to U.S. defense and aerospace customers.
The server also contained an eb.sys file matching GentleKiller, a driver previously linked to The Gentlemen, reinforcing the connection. Evidence suggests the group used AI-assisted development for TukTuk, marking a growing trend in ransomware operations.
Source: https://cyberpress.org/ransomware-c2-disarms-defenses/
Hetzner Online TPRM report: https://www.rankiteo.com/company/hetzner-online
"id": "het1788337502",
"linkid": "hetzner-online",
"type": "Cyber Attack",
"date": "9/2026",
"severity": "25",
"impact": "1",
"explanation": "Attack without any consequences"
{'affected_entities': [{'customers_affected': 'U.S. defense and aerospace '
'customers',
'industry': 'Technology',
'location': 'Global',
'name': 'Global tech company (unspecified)',
'type': 'Corporation'},
{'location': 'Global',
'name': 'Unspecified second global company',
'type': 'Corporation'}],
'attack_vector': 'Command-and-Control (C2) Framework',
'data_breach': {'data_exfiltration': 'Yes',
'number_of_records_exposed': '224 Jira tickets and eight '
'attachments',
'personally_identifiable_information': 'Credentials and '
'sensitive information',
'sensitivity_of_data': 'High (U.S. defense and '
'aerospace-related)',
'type_of_data_compromised': ['Jira tickets',
'Attachments',
'Credentials',
'Infrastructure details']},
'description': 'Threat intelligence researchers uncovered a '
'command-and-control (C2) server tied to the ransomware group '
'The Gentlemen, revealing a previously undocumented framework '
'called TukTuk, tools to disable endpoint security, and stolen '
'corporate data from two global companies. The server hosted '
'the full TukTuk v2.0 project, including Windows and Linux '
'agents, a backend server, and an operator control panel. The '
'framework enables attackers to monitor compromised devices, '
'execute commands, manage files, capture screenshots, and '
'harvest credentials via a fake Windows Security prompt.',
'impact': {'data_compromised': '224 Jira tickets and eight attachments '
'containing infrastructure details, '
'credentials, and sensitive information '
'related to U.S. defense and aerospace '
'customers',
'identity_theft_risk': 'High (credentials and sensitive '
'information harvested)',
'systems_affected': 'Compromised devices (Windows and Linux)'},
'post_incident_analysis': {'root_causes': 'Use of TukTuk C2 framework, DLL '
'sideloading, BYOVD techniques, and '
'AI-assisted development'},
'ransomware': {'data_exfiltration': 'Yes'},
'references': [{'source': 'Threat intelligence researchers'}],
'threat_actor': 'The Gentlemen',
'title': 'Newly Discovered TukTuk C2 Framework Linked to The Gentlemen '
'Ransomware Group',
'type': 'Ransomware',
'vulnerability_exploited': 'DLL sideloading (log4net.dll), BYOVD (Bring Your '
'Own Vulnerable Driver) techniques'}