EtherRAT and TukTuk C2 Lead to The Gentlemen Ransomware Deployment

Summary
A DFIR investigation details an intrusion that began with a malicious MSI, used EtherRAT and TukTuk for access and C2, exfiltrated data to Wasabi, and ended in domain-wide The Gentlemen ransomware deployment.
Key points
- The intrusion began when a user ran an MSI masquerading as the Sysinternals RAMMap utility; it installed EtherRAT and established persistence through a registry Run key.
- EtherRAT used Ethereum-hosted configuration and TryCloudflare tunnels for C2. TukTuk was deployed through DLL sideloading in disguised Greenshot and other legitimate applications.
- The actors used GoTo Resolve for lateral access, performed Active Directory reconnaissance and credential theft, and expanded through RDP, SMB, and WinRM.
- Rclone was used to exfiltrate sensitive data to Wasabi cloud storage before ransomware deployment.
- The Gentlemen ransomware deployment disabled defenses, deleted recovery data and forensic artifacts, and spread across the domain through a malicious Group Policy Object.
- The report provides hunting guidance for suspicious MSI execution, registry persistence, credential dumping, abused SaaS and blockchain services, unauthorized RMM use, and Rclone activity.
Article Details
- Attack Vectors
- In the observed intrusion, a user executed a malicious MSI masquerading as the Sysinternals RAMMap utility, installing EtherRAT.
- EtherRAT retrieved C2 configuration through an Ethereum smart contract; the actor later updated it to point to a TryCloudflare tunnel.
- The actor downloaded additional payloads from S3 buckets and deployed TukTuk variants through DLL sideloading with legitimate application binaries.
- Compromised service account credentials were used to deploy GoTo Resolve across multiple systems.
- The actor used Rclone to exfiltrate data to Wasabi storage, then deployed The Gentlemen ransomware domain-wide through a malicious GPO and scheduled tasks.
- Defensive Notes
- Investigate MSI execution from user Desktop or Downloads locations that spawns unexpected child processes, and unusual registry Run keys.
- Monitor unauthorized RMM installations and connections to blockchain gateways, tunneling services, and SaaS platforms from hosts that do not normally use them. Shared service domains are not necessarily suitable for direct blocking.
- Hunt for unexpected outbound connections or unusual execution paths involving Greenshot.exe, SyncTrayzor.exe, docfx.exe, and Cake.exe.
- Monitor LSASS dumping, anomalous discovery commands, NetExec activity, and Rclone transfers to unapproved cloud storage.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | borjumaniya[.]store | Listed fallback HTTP C2 domain. |
| HOSTNAME | ep-lively-cherry-a80bmwii[.]eastus2[.]azure[.]neon[.]tech | Neon hostname listed as infrastructure seen in a related campaign. |
| HOSTNAME | k135neflez[.]westus3[.]azure[.]clickhouse[.]cloud | Specific ClickHouse hostname listed as TukTuk C2-related infrastructure. |
| HOSTNAME | muurfzqprzmdkzoibxaz[.]supabase[.]co | Supabase hostname listed as infrastructure seen in a related campaign. |
| HOSTNAME | vefbdzzuaadnascpeqcn[.]supabase[.]co | Specific Supabase hostname listed as TukTuk C2-related infrastructure. |
| HOSTNAME | vngz3ntdrb[.]us-east1[.]gcp[.]clickhouse[.]cloud | ClickHouse hostname listed as infrastructure seen in a related campaign. |
| MD5 | 73ce2438d4ed475e03727b7b000d2794 | Hash listed for the malicious initial-access RAMMap.msi. |
| MD5 | 77fbe265fd65c7f7b6d323fb6de6a4fd | Hash listed for the EtherRAT-associated v72HYLU3OpRBznc.ini. |
| MD5 | b188fbc6ff5557767e73e4c883a553a3 | Hash listed for smokymo.msi, associated with the actor's GoTo Resolve deployment. |
| MD5 | b2d51212744f404714fd909e87254d98 | Hash listed for the EtherRAT-associated MVnVmUYj.cmd. |
| MD5 | c92cf9a1af5b1fe25cdcb8771ce52be4 | Hash listed for the EtherRAT-associated A7Pnj975bl.cfg. |
| MD5 | f985b8d6d635c266fc4779dad77aa75c | Hash listed for the TukTuk-associated log4net.dll. |
| SHA1 | 114ec028a3fc4ed50056ee8166b0c39acff6ff03 | Hash listed for the EtherRAT-associated v72HYLU3OpRBznc.ini. |
| SHA1 | 3d5ee8429ef00824c0351cba507dfeb92b54f83b | Hash listed for the malicious initial-access RAMMap.msi. |
| SHA1 | aa9218994798ae31a19d3e7e39cfac2e2ee55840 | Hash listed for smokymo.msi, associated with the actor's GoTo Resolve deployment. |
| SHA1 | b44c8084b88d31113ee51758740eb84c251bdae8 | Hash listed for the EtherRAT-associated A7Pnj975bl.cfg. |
| SHA1 | ba80d7b038758a129861e1e498e462cc3d68ae20 | Hash listed for the TukTuk-associated log4net.dll. |
| SHA1 | c98ee41f09ae079a5643626f57eb84f92205bb2b | Hash listed for the EtherRAT-associated MVnVmUYj.cmd. |
| SHA256 | 1795eacd2c58894ccdd6be8854fe6456c3b069a3a873432343b57b475b256aee | Hash listed for smokymo.msi, associated with the actor's GoTo Resolve deployment. |
| SHA256 | 19021e53b9929fdf4b7d0e0707434d56bb73c1a9b7403c8837b44d1c417198dc | Hash listed for the TukTuk-associated log4net.dll. |
| SHA256 | 2d4b4bb18b8445e49eeda571982874403befcecf78266e3d405f6529d98bee46 | Hash listed for the EtherRAT-associated v72HYLU3OpRBznc.ini. |
| SHA256 | 4142d5efd4ea2abab77f2f0a917610e2ff976bf9e19d7ad1e9156eccdc5412db | Hash listed for the EtherRAT-associated A7Pnj975bl.cfg. |
| SHA256 | 8c2665adf8bfab65463f2a9bd1b7bb0231de3f5c1e6a2e51479e44aaac2e7bf0 | Hash listed for the EtherRAT-associated MVnVmUYj.cmd. |
| SHA256 | d9487fdc097f770e5661f9e5dee130068cb179d33716abff1a21c8cb901f25a6 | Hash listed for the malicious initial-access RAMMap.msi. |
| URL | hxxps[:]//afford-effect-construct-tricks[.]trycloudflare[.]com | TryCloudflare URL listed among the actor's C2-related infrastructure, including possible decoys. |
| URL | hxxps[:]//entered-medications-motherboard-advanced[.]trycloudflare[.]com | TryCloudflare URL listed among the actor's C2-related infrastructure, including possible decoys. |
| URL | hxxps[:]//fields-pct-easier-vancouver[.]trycloudflare[.]com | TryCloudflare URL listed among the actor's C2-related infrastructure, including possible decoys. |
| URL | hxxps[:]//howto-tar-naturals-coordination[.]trycloudflare[.]com | TryCloudflare URL listed among the actor's C2-related infrastructure, including possible decoys. |
| URL | hxxps[:]//mode-exit-legendary-trusted[.]trycloudflare[.]com | TryCloudflare URL listed among the actor's C2-related infrastructure, including possible decoys. |
| URL | hxxps[:]//rapids-lil-lending-charleston[.]trycloudflare[.]com | TryCloudflare URL listed among the actor's C2-related infrastructure, including possible decoys. |
| URL | hxxps[:]//seasonal-estimation-heating-necessarily[.]trycloudflare[.]com | TryCloudflare URL listed among the actor's C2-related infrastructure, including possible decoys. |
| URL | hxxps[:]//walt-messaging-affairs-occurring[.]trycloudflare[.]com | TryCloudflare URL listed among the actor's C2-related infrastructure, including possible decoys. |
| URL | hxxps[:]//when-architectural-cdna-faster[.]trycloudflare[.]com | TryCloudflare URL listed among the actor's C2-related infrastructure, including possible decoys. |
| URL | hxxps[:]//witch-skins-lip-coal[.]trycloudflare[.]com | TryCloudflare tunnel URL listed as intrusion-related C2 infrastructure. |
| URL | hxxps[:]//workshop-lighting-protective-customs[.]trycloudflare[.]com | TryCloudflare URL listed among the actor's C2-related infrastructure, including possible decoys. |
MITRE ATT&CK
T1003.001 · LSASS MemoryThe intrusion included LSASS dumping activity, with a detection example using comsvcs.dll.T1003.003 · NTDSThe intrusion included NTDS dumping activity, and the report shows a NetExec --ntds command.T1021.001 · Remote Desktop ProtocolThe actor expanded access through RDP.T1021.002 · SMB/Windows Admin SharesThe actor expanded access through SMB.T1021.006 · Windows Remote ManagementThe actor expanded access through WinRM.T1036.005 · Match Legitimate Resource Name or LocationThe initial MSI masqueraded as RAMMap, and TukTuk payloads were disguised as legitimate application binaries.T1053.005 · Scheduled TaskThe malicious GPO executed staged ransomware binaries through scheduled tasks.T1070.001 · Clear Windows Event LogsThe actor cleared event logs before ransomware encryption.T1078.002 · Domain AccountsCompromised service account credentials were used to deploy GoTo Resolve laterally.T1105 · Ingress Tool TransferThe actor downloaded additional payloads from S3 buckets.T1204.002 · Malicious FileA user executed the malicious MSI masquerading as RAMMap.T1484.001 · Group Policy ModificationThe actor used a malicious GPO for domain-wide ransomware deployment.T1486 · Data Encrypted for ImpactThe Gentlemen ransomware encrypted impacted systems across the domain.T1490 · Inhibit System RecoveryThe actor deleted shadow copies before ransomware encryption.T1547.001 · Registry Run Keys / Startup FolderEtherRAT established persistence through an AppResolver registry Run key.T1558.003 · KerberoastingThe actor conducted Kerberoasting operations after TukTuk execution.T1562.001 · Disable or Modify ToolsBefore encryption, the actor disabled Microsoft Defender protections and added AV exclusions.T1567.002 · Exfiltration to Cloud StorageThe actor used Rclone to exfiltrate sensitive data to Wasabi cloud storage.T1574.002 · DLL Side-LoadingTukTuk variants executed through DLL sideloading with legitimate application binaries.
CVE
People
Malware
EtherRATThe EtherRAT malware family was first reported by Sysdig back in December 2025.The GentlemenUsing this access, they successfully exfiltrated data to a cloud service and then deployed The Gentlemen ransomware.TukTukLater in the intrusion, we observed the deployment of a new malware framework named TukTuk, first reported by Evangelos G, which, according to their analysis, is AI-generated.
Vendors
ClickHouseThese trojanized payloads established primary C2 channels through SaaS platforms ClickHouse and Supabase, with secondary backup channels capable of leveraging Ably, Dropbox, direct HTTP, or GitHub Issues.CloudflareThe actors also used trycloudflare.com tunnel addresses, allowing remote access to the environment over a Cloudflare tunnel.GoToIn addition to this, the threat actor used the RMM GoTo Resolve.MicrosoftPrior to encryption, the actor disabled Microsoft Defender protections, added AV exclusions, stopped virtual machines, deleted shadow copies, cleared event logs, and removed forensic artifacts.SupabaseThese trojanized payloads established primary C2 channels through SaaS platforms ClickHouse and Supabase, with secondary backup channels capable of leveraging Ably, Dropbox, direct HTTP, or GitHub Issues.WasabiConcurrently, the actor staged and executed Rclone to exfiltrate large volumes of sensitive data to Wasabi cloud storage before deploying additional TukTuk implants across critical infrastructure.
Products
CakeWhile Expel has previously reported on Greenshot being abused this way, we also observed the same sideloading technique applied to SyncTrayzor, the DocFX document generator, and the Cake build automation system.DocFXWhile Expel has previously reported on Greenshot being abused this way, we also observed the same sideloading technique applied to SyncTrayzor, the DocFX document generator, and the Cake build automation system.GoTo ResolveIn addition to this, the threat actor used the RMM GoTo Resolve.GreenshotThe actor then downloaded additional payloads from S3 buckets, ultimately deploying TukTuk malware variants disguised as Greenshot binaries and executed via DLL sideloading.Microsoft DefenderPrior to encryption, the actor disabled Microsoft Defender protections, added AV exclusions, stopped virtual machines, deleted shadow copies, cleared event logs, and removed forensic artifacts.Microsoft WindowsIn March 2026, a Windows variant campaign was reported by Atos, with their investigation showing evidence of activity going back to the previous December.Node.jsAfter execution, the malware downloaded a portable Node.js runtime, launched obfuscated JavaScript payloads, and established persistence through a registry Run key.RAMMapIn April, we observed a user execute a malicious MSI installer masquerading as the Sysinternals RAMMap utility.SyncTrayzorWhile Expel has previously reported on Greenshot being abused this way, we also observed the same sideloading technique applied to SyncTrayzor, the DocFX document generator, and the Cake build automation system.
Tools
MimikatzOver the following days, they expanded access through RDP, SMB, WinRM, NetExec (nxc), Mimikatz, and LSASS/NTDS dumping activity while resetting privileged account passwords and conducting broad Active DirectoryNetExecOver the following days, they expanded access through RDP, SMB, WinRM, NetExec (nxc), Mimikatz, and LSASS/NTDS dumping activity while resetting privileged account passwords and conducting broad Active DirectoryRCloneConcurrently, the actor staged and executed Rclone to exfiltrate large volumes of sensitive data to Wasabi cloud storage before deploying additional TukTuk implants across critical infrastructure.SoftPerfect Network ScannerSoftperfect Network Scanner continues to be a favored tool in this and many other intrusions we observe.