Image: thedfirreport.com · rights & removal
Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware
Reporting by The DFIR ReportRead the original at thedfirreport.com
Executive Summary
In April, a sophisticated intrusion was observed involving the Gentlemen Ransomware (GER), EtherRAT (E), and TukTuk malware. The article outlines the key stages of this attack, from initial access via Atos campaigns to post-ransomware deployment over Group Policy Object (GPO) scheduled tasks. It includes details on command-and-control (C2) infrastructure, persistence through registry keys, domain reconnaissance, host-based detection, and remote execution. Notably, it mentions the Ethereum blockchain for configuration updates and the use of RMM tooling like GoTo Resolve for lateral movement.
The intrusion highlights a blend of traditional and decentralized C2 infrastructures, leveraging SaaS platforms and public tunnel services. The threat actor utilized NetExec for lateral movement and compromised service accounts to bypass security measures on various systems. This multi-layered approach ensured the stealthy execution and wide-ranging impact of the attack. The article also notes that the intrusion involved several legitimate tools such as Greenshot, SyncTrayzor, DocFX, and Cake, which were modified to conceal malicious activity.
The detection process is detailed using indicators like TLS SNI (1rpc.io) and DNS queries to common abuse domains. Automated rules based on ET OPEN indicate the presence of various cloud storage services being used for data exfiltration. The threat actor's methods demonstrate a shift towards more sophisticated techniques, including leveraging RMM tooling as C2 channels, which is becoming a common practice in many intrusions.
The article concludes by advising readers to approach this intrusion with a balanced perspective, recognizing the multi-layered nature of cyber threats and staying alert for similar tactics.
Facts Only
In late 2025 and continuing into 2026, threat actors have increasingly used NetExec for lateral movement in intrusions. They deploy RMM tooling like GoTo Resolve as C2 channels, often targeting compromised service accounts to bypass security measures on various systems.
The intrusion involved a mix of decentralized infrastructure, public tunnel services, SaaS platforms, and RMM tooling to maintain access and retrieve configuration data. The threat actor used 1rpc.io for Ethereum blockchain-based C2 resolution and Arweave for dead-drop resolutions involving Drive-Ids hardcoded in transactions.
Full Take
In this intrusion, the threat actors employed a variety of patterns that challenge traditional notions of cyber security:
**Emotional Exploitation**: The use of fear appeals to justify encryption removal post-ransomware deployment.
**Distortion**: Misleading framing about vulnerability handling capabilities in various cloud storage services.
**Bad Faith**: Using popular opinion to suggest a specific solution, ignoring alternatives that may exist.
The article also suggests several implications:
It highlights the growing sophistication of cyber threats and the importance of continuous vigilance against new attack vectors such as RMM tooling used for C2 communication over legitimate service accounts.
The intrusion underscores the need for understanding approved SaaS platforms within organizations to avoid misuse by malicious actors.
The detection techniques include TLS SNI inspection, DNS lookups, and specific indicators that can be flagged using certain A.R.C. rules like "2058739: ET INFO Observed Smart Chain Domain in DNS Lookup."
From the original · The DFIR Report
Background The EtherRAT malware family was first reported by Sysdig back in December 2025. At that time, the initial access vector was exploitation of CVE-2025-55182 (React2Shell) targeting Linux servers.Read the full story at thedfirreport.com
Sentinel — Human
This text appears to be an AI-generated document with a balanced synthesis of information but lacks emotional depth and individual perspectives.
