Hetzner Online: Ransomware Hackers Built Their Own C2 Framework to Steal Passwords and Kill Security Tools

Hetzner Online: Ransomware Hackers Built Their Own C2 Framework to Steal Passwords and Kill Security Tools

Newly Discovered TukTuk C2 Framework Linked to The Gentlemen Ransomware Group

Threat intelligence researchers uncovered a command-and-control (C2) server tied to the ransomware group The Gentlemen, revealing a previously undocumented framework called TukTuk, tools to disable endpoint security, and stolen corporate data from two global companies.

The server, hosted by Hetzner Online in Finland (IP: 65.109.70.162), contained the full TukTuk v2.0 project, including Windows and Linux agents, a backend server, and an operator control panel. The framework enables attackers to monitor compromised devices, execute commands, manage files, capture screenshots, and harvest credentials via a fake Windows Security prompt.

Key findings include:

  • Cross-platform capabilities: The Windows agent (C#) and Linux agent demonstrate TukTuk’s versatility beyond Windows-only attacks.
  • DLL sideloading techniques: A malicious log4net.dll disguised as part of the legitimate Greenshot application was found, along with research on sideloading opportunities in ProcMon, Slack, and Postman.
  • EDR-killing tools: The server hosted materials on BYOVD (Bring Your Own Vulnerable Driver) techniques, including files like EDRKiller, WarsawKiller, and an unidentified driver still lacking a CVE.
  • Stolen data: 224 Jira tickets and eight attachments from a global tech company were recovered, containing infrastructure details, credentials, and sensitive information related to U.S. defense and aerospace customers.

The server also contained an eb.sys file matching GentleKiller, a driver previously linked to The Gentlemen, reinforcing the connection. Evidence suggests the group used AI-assisted development for TukTuk, marking a growing trend in ransomware operations.

Source: https://cyberpress.org/ransomware-c2-disarms-defenses/

Hetzner Online TPRM report: https://www.rankiteo.com/company/hetzner-online

"id": "het1788337502",
"linkid": "hetzner-online",
"type": "Cyber Attack",
"date": "9/2026",
"severity": "25",
"impact": "1",
"explanation": "Attack without any consequences"
{'affected_entities': [{'customers_affected': 'U.S. defense and aerospace '
                                              'customers',
                        'industry': 'Technology',
                        'location': 'Global',
                        'name': 'Global tech company (unspecified)',
                        'type': 'Corporation'},
                       {'location': 'Global',
                        'name': 'Unspecified second global company',
                        'type': 'Corporation'}],
 'attack_vector': 'Command-and-Control (C2) Framework',
 'data_breach': {'data_exfiltration': 'Yes',
                 'number_of_records_exposed': '224 Jira tickets and eight '
                                              'attachments',
                 'personally_identifiable_information': 'Credentials and '
                                                        'sensitive information',
                 'sensitivity_of_data': 'High (U.S. defense and '
                                        'aerospace-related)',
                 'type_of_data_compromised': ['Jira tickets',
                                              'Attachments',
                                              'Credentials',
                                              'Infrastructure details']},
 'description': 'Threat intelligence researchers uncovered a '
                'command-and-control (C2) server tied to the ransomware group '
                'The Gentlemen, revealing a previously undocumented framework '
                'called TukTuk, tools to disable endpoint security, and stolen '
                'corporate data from two global companies. The server hosted '
                'the full TukTuk v2.0 project, including Windows and Linux '
                'agents, a backend server, and an operator control panel. The '
                'framework enables attackers to monitor compromised devices, '
                'execute commands, manage files, capture screenshots, and '
                'harvest credentials via a fake Windows Security prompt.',
 'impact': {'data_compromised': '224 Jira tickets and eight attachments '
                                'containing infrastructure details, '
                                'credentials, and sensitive information '
                                'related to U.S. defense and aerospace '
                                'customers',
            'identity_theft_risk': 'High (credentials and sensitive '
                                   'information harvested)',
            'systems_affected': 'Compromised devices (Windows and Linux)'},
 'post_incident_analysis': {'root_causes': 'Use of TukTuk C2 framework, DLL '
                                           'sideloading, BYOVD techniques, and '
                                           'AI-assisted development'},
 'ransomware': {'data_exfiltration': 'Yes'},
 'references': [{'source': 'Threat intelligence researchers'}],
 'threat_actor': 'The Gentlemen',
 'title': 'Newly Discovered TukTuk C2 Framework Linked to The Gentlemen '
          'Ransomware Group',
 'type': 'Ransomware',
 'vulnerability_exploited': 'DLL sideloading (log4net.dll), BYOVD (Bring Your '
                            'Own Vulnerable Driver) techniques'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.