EtherRAT and TukTuk C2 Lead to The Gentlemen Ransomware Deployment

· Original article ↗

Summary

A DFIR investigation details an intrusion that began with a malicious MSI, used EtherRAT and TukTuk for access and C2, exfiltrated data to Wasabi, and ended in domain-wide The Gentlemen ransomware deployment.

Key points

  • The intrusion began when a user ran an MSI masquerading as the Sysinternals RAMMap utility; it installed EtherRAT and established persistence through a registry Run key.
  • EtherRAT used Ethereum-hosted configuration and TryCloudflare tunnels for C2. TukTuk was deployed through DLL sideloading in disguised Greenshot and other legitimate applications.
  • The actors used GoTo Resolve for lateral access, performed Active Directory reconnaissance and credential theft, and expanded through RDP, SMB, and WinRM.
  • Rclone was used to exfiltrate sensitive data to Wasabi cloud storage before ransomware deployment.
  • The Gentlemen ransomware deployment disabled defenses, deleted recovery data and forensic artifacts, and spread across the domain through a malicious Group Policy Object.
  • The report provides hunting guidance for suspicious MSI execution, registry persistence, credential dumping, abused SaaS and blockchain services, unauthorized RMM use, and Rclone activity.

Article Details

Attack Vectors
  • In the observed intrusion, a user executed a malicious MSI masquerading as the Sysinternals RAMMap utility, installing EtherRAT.
  • EtherRAT retrieved C2 configuration through an Ethereum smart contract; the actor later updated it to point to a TryCloudflare tunnel.
  • The actor downloaded additional payloads from S3 buckets and deployed TukTuk variants through DLL sideloading with legitimate application binaries.
  • Compromised service account credentials were used to deploy GoTo Resolve across multiple systems.
  • The actor used Rclone to exfiltrate data to Wasabi storage, then deployed The Gentlemen ransomware domain-wide through a malicious GPO and scheduled tasks.
Defensive Notes
  • Investigate MSI execution from user Desktop or Downloads locations that spawns unexpected child processes, and unusual registry Run keys.
  • Monitor unauthorized RMM installations and connections to blockchain gateways, tunneling services, and SaaS platforms from hosts that do not normally use them. Shared service domains are not necessarily suitable for direct blocking.
  • Hunt for unexpected outbound connections or unusual execution paths involving Greenshot.exe, SyncTrayzor.exe, docfx.exe, and Cake.exe.
  • Monitor LSASS dumping, anomalous discovery commands, NetExec activity, and Rclone transfers to unapproved cloud storage.

Indicators of compromise

TypeIndicatorContext
DOMAINborjumaniya[.]storeListed fallback HTTP C2 domain.
HOSTNAMEep-lively-cherry-a80bmwii[.]eastus2[.]azure[.]neon[.]techNeon hostname listed as infrastructure seen in a related campaign.
HOSTNAMEk135neflez[.]westus3[.]azure[.]clickhouse[.]cloudSpecific ClickHouse hostname listed as TukTuk C2-related infrastructure.
HOSTNAMEmuurfzqprzmdkzoibxaz[.]supabase[.]coSupabase hostname listed as infrastructure seen in a related campaign.
HOSTNAMEvefbdzzuaadnascpeqcn[.]supabase[.]coSpecific Supabase hostname listed as TukTuk C2-related infrastructure.
HOSTNAMEvngz3ntdrb[.]us-east1[.]gcp[.]clickhouse[.]cloudClickHouse hostname listed as infrastructure seen in a related campaign.
MD573ce2438d4ed475e03727b7b000d2794Hash listed for the malicious initial-access RAMMap.msi.
MD577fbe265fd65c7f7b6d323fb6de6a4fdHash listed for the EtherRAT-associated v72HYLU3OpRBznc.ini.
MD5b188fbc6ff5557767e73e4c883a553a3Hash listed for smokymo.msi, associated with the actor's GoTo Resolve deployment.
MD5b2d51212744f404714fd909e87254d98Hash listed for the EtherRAT-associated MVnVmUYj.cmd.
MD5c92cf9a1af5b1fe25cdcb8771ce52be4Hash listed for the EtherRAT-associated A7Pnj975bl.cfg.
MD5f985b8d6d635c266fc4779dad77aa75cHash listed for the TukTuk-associated log4net.dll.
SHA1114ec028a3fc4ed50056ee8166b0c39acff6ff03Hash listed for the EtherRAT-associated v72HYLU3OpRBznc.ini.
SHA13d5ee8429ef00824c0351cba507dfeb92b54f83bHash listed for the malicious initial-access RAMMap.msi.
SHA1aa9218994798ae31a19d3e7e39cfac2e2ee55840Hash listed for smokymo.msi, associated with the actor's GoTo Resolve deployment.
SHA1b44c8084b88d31113ee51758740eb84c251bdae8Hash listed for the EtherRAT-associated A7Pnj975bl.cfg.
SHA1ba80d7b038758a129861e1e498e462cc3d68ae20Hash listed for the TukTuk-associated log4net.dll.
SHA1c98ee41f09ae079a5643626f57eb84f92205bb2bHash listed for the EtherRAT-associated MVnVmUYj.cmd.
SHA2561795eacd2c58894ccdd6be8854fe6456c3b069a3a873432343b57b475b256aeeHash listed for smokymo.msi, associated with the actor's GoTo Resolve deployment.
SHA25619021e53b9929fdf4b7d0e0707434d56bb73c1a9b7403c8837b44d1c417198dcHash listed for the TukTuk-associated log4net.dll.
SHA2562d4b4bb18b8445e49eeda571982874403befcecf78266e3d405f6529d98bee46Hash listed for the EtherRAT-associated v72HYLU3OpRBznc.ini.
SHA2564142d5efd4ea2abab77f2f0a917610e2ff976bf9e19d7ad1e9156eccdc5412dbHash listed for the EtherRAT-associated A7Pnj975bl.cfg.
SHA2568c2665adf8bfab65463f2a9bd1b7bb0231de3f5c1e6a2e51479e44aaac2e7bf0Hash listed for the EtherRAT-associated MVnVmUYj.cmd.
SHA256d9487fdc097f770e5661f9e5dee130068cb179d33716abff1a21c8cb901f25a6Hash listed for the malicious initial-access RAMMap.msi.
URLhxxps[:]//afford-effect-construct-tricks[.]trycloudflare[.]comTryCloudflare URL listed among the actor's C2-related infrastructure, including possible decoys.
URLhxxps[:]//entered-medications-motherboard-advanced[.]trycloudflare[.]comTryCloudflare URL listed among the actor's C2-related infrastructure, including possible decoys.
URLhxxps[:]//fields-pct-easier-vancouver[.]trycloudflare[.]comTryCloudflare URL listed among the actor's C2-related infrastructure, including possible decoys.
URLhxxps[:]//howto-tar-naturals-coordination[.]trycloudflare[.]comTryCloudflare URL listed among the actor's C2-related infrastructure, including possible decoys.
URLhxxps[:]//mode-exit-legendary-trusted[.]trycloudflare[.]comTryCloudflare URL listed among the actor's C2-related infrastructure, including possible decoys.
URLhxxps[:]//rapids-lil-lending-charleston[.]trycloudflare[.]comTryCloudflare URL listed among the actor's C2-related infrastructure, including possible decoys.
URLhxxps[:]//seasonal-estimation-heating-necessarily[.]trycloudflare[.]comTryCloudflare URL listed among the actor's C2-related infrastructure, including possible decoys.
URLhxxps[:]//walt-messaging-affairs-occurring[.]trycloudflare[.]comTryCloudflare URL listed among the actor's C2-related infrastructure, including possible decoys.
URLhxxps[:]//when-architectural-cdna-faster[.]trycloudflare[.]comTryCloudflare URL listed among the actor's C2-related infrastructure, including possible decoys.
URLhxxps[:]//witch-skins-lip-coal[.]trycloudflare[.]comTryCloudflare tunnel URL listed as intrusion-related C2 infrastructure.
URLhxxps[:]//workshop-lighting-protective-customs[.]trycloudflare[.]comTryCloudflare URL listed among the actor's C2-related infrastructure, including possible decoys.

MITRE ATT&CK

T1003.001 · LSASS MemoryThe intrusion included LSASS dumping activity, with a detection example using comsvcs.dll.T1003.003 · NTDSThe intrusion included NTDS dumping activity, and the report shows a NetExec --ntds command.T1021.001 · Remote Desktop ProtocolThe actor expanded access through RDP.T1021.002 · SMB/Windows Admin SharesThe actor expanded access through SMB.T1021.006 · Windows Remote ManagementThe actor expanded access through WinRM.T1036.005 · Match Legitimate Resource Name or LocationThe initial MSI masqueraded as RAMMap, and TukTuk payloads were disguised as legitimate application binaries.T1053.005 · Scheduled TaskThe malicious GPO executed staged ransomware binaries through scheduled tasks.T1070.001 · Clear Windows Event LogsThe actor cleared event logs before ransomware encryption.T1078.002 · Domain AccountsCompromised service account credentials were used to deploy GoTo Resolve laterally.T1105 · Ingress Tool TransferThe actor downloaded additional payloads from S3 buckets.T1204.002 · Malicious FileA user executed the malicious MSI masquerading as RAMMap.T1484.001 · Group Policy ModificationThe actor used a malicious GPO for domain-wide ransomware deployment.T1486 · Data Encrypted for ImpactThe Gentlemen ransomware encrypted impacted systems across the domain.T1490 · Inhibit System RecoveryThe actor deleted shadow copies before ransomware encryption.T1547.001 · Registry Run Keys / Startup FolderEtherRAT established persistence through an AppResolver registry Run key.T1558.003 · KerberoastingThe actor conducted Kerberoasting operations after TukTuk execution.T1562.001 · Disable or Modify ToolsBefore encryption, the actor disabled Microsoft Defender protections and added AV exclusions.T1567.002 · Exfiltration to Cloud StorageThe actor used Rclone to exfiltrate sensitive data to Wasabi cloud storage.T1574.002 · DLL Side-LoadingTukTuk variants executed through DLL sideloading with legitimate application binaries.

CVE

People

Malware

Vendors

Products

CakeWhile Expel has previously reported on Greenshot being abused this way, we also observed the same sideloading technique applied to SyncTrayzor, the DocFX document generator, and the Cake build automation system.DocFXWhile Expel has previously reported on Greenshot being abused this way, we also observed the same sideloading technique applied to SyncTrayzor, the DocFX document generator, and the Cake build automation system.GoTo ResolveIn addition to this, the threat actor used the RMM GoTo Resolve.GreenshotThe actor then downloaded additional payloads from S3 buckets, ultimately deploying TukTuk malware variants disguised as Greenshot binaries and executed via DLL sideloading.Microsoft DefenderPrior to encryption, the actor disabled Microsoft Defender protections, added AV exclusions, stopped virtual machines, deleted shadow copies, cleared event logs, and removed forensic artifacts.Microsoft WindowsIn March 2026, a Windows variant campaign was reported by Atos, with their investigation showing evidence of activity going back to the previous December.Node.jsAfter execution, the malware downloaded a portable Node.js runtime, launched obfuscated JavaScript payloads, and established persistence through a registry Run key.RAMMapIn April, we observed a user execute a malicious MSI installer masquerading as the Sysinternals RAMMap utility.SyncTrayzorWhile Expel has previously reported on Greenshot being abused this way, we also observed the same sideloading technique applied to SyncTrayzor, the DocFX document generator, and the Cake build automation system.

Tools

Related Articles