
Ransomware operators are using a previously undocumented remote-control framework called TukTuk to steal credentials, watch compromised machines, and weaken protections. The discovery links the tool to activity associated with the Gentlemen ransomware operation and shows how one intrusion can combine access theft, surveillance, and defense evasion.
Its recovery gives defenders an unusual view of the infrastructure and research that can sit behind a ransomware operation. The framework was recovered from a server holding a malicious DLL sideloading set, EDR-disabling tools, and data believed taken from two large organizations. That mix suggests a prepared attack environment, able to move from an initial foothold to data theft and ransomware deployment.
It also gives incident responders several distinct traces to investigate. That breadth complicates containment and raises the risk of repeat intrusion. Oasis Security analysts identified the complete TukTuk project, including Windows and Linux agents, a backend, and an operator panel.
EDRKiller and WarsawKiller…
➪ Continue reading the full article on cybersecuritynews.com









