Ransomware Hackers Built Their Own C2 Framework to Steal Passwords and Kill Security Tools

A newly analyzed server linked to the ransomware group The Gentlemen contained a previously undocumented command-and-control (C2) framework called TukTuk, tools designed to disable endpoint security products, and data believed to have been stolen from two global companies.

Threat intelligence researchers identified the server at IP address 65.109.70.162, hosted by Hetzner Online in Finland.

The collected files included the full TukTuk C2 project, malicious DLL sideloading components, EDR-killing tools, vulnerable-driver research, and exfiltrated corporate information.

Researchers said the evidence connects the infrastructure to The Gentlemen ransomware operation. One major indicator was an eb.sys file whose hash matched GentleKiller, a driver previously associated with the group.

The server also contained a Greenshot DLL sideloading package consistent with techniques previously linked to The Gentlemen.

Ransomware C2 Disarms Defenses

The complete TukTuk v2.0 project archive was found on the server, including separate Windows and Linux agents, a backend server component, and an operator control panel.

Researchers said they could not find any earlier public disclosure or documentation for the full project structure.

TukTuk C2 dashboard showing hostname DESKTOP-22EVPBQ (Source: oasis)
TukTuk C2 dashboard showing hostname DESKTOP-22EVPBQ (Source: oasis)

TukTuk allows operators to monitor compromised devices, run commands, manage files, capture screenshots, and control running processes.

Its panel includes a credential-focused feature that can display a fake Windows Security prompt on infected systems. Credentials entered into the spoofed prompt are then recorded by the framework.

The Windows agent was written in C#, while the management panel used Node.js and Electron. The discovery of a dedicated Linux agent shows that TukTuk was designed for cross-platform operations rather than Windows-only attacks.

Researchers also found a malicious log4net.dll designed to be loaded by the legitimate Greenshot application. This DLL sideloading technique can launch the TukTuk agent while making execution appear connected to trusted software.

The malicious DLL contained C2 configuration data and references to Slack, GitHub, Dropbox, and a previously identified malicious domain.

The server further contained research folders examining DLL sideloading opportunities involving Greenshot, ProcMon, Slack, and Postman.

Screenshot indicating TukTuk C2 development was carried out using artificial intelligence (Source: oasis)
Screenshot indicating TukTuk C2 development was carried out using artificial intelligence (Source: oasis)

The server hosted step-by-step materials for neutralizing endpoint detection and response (EDR) tools. These resources covered known EDR-killing software, Bring Your Own Vulnerable Driver (BYOVD) techniques, driver testing, and kernel-level research.

Files named EDRKiller, WarsawKiller, UnknownKiller, and wsftprm.sys were identified alongside training documents organized into four lessons.

The materials reportedly examined how security tools respond after their processes are terminated and how attackers could identify vulnerable Windows drivers usable in real attacks, oasis said.

Researchers also found a document indicating work on a potentially undisclosed vulnerable driver that had not yet received a CVE identifier.

Alongside the attack tools, the server contained 224 Jira tickets and eight attachments believed to have been stolen from a global technology company.

The records included technical support data, infrastructure details, credentials, vulnerability information, and material involving U.S. defense, aerospace, and defense-industry customers.

Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN-> Power your SOC with ANY.RUN

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories