Ransomware Hackers Use New TukTuk Malware to Steal Credentials and Disable Security Tools | #ransomware | #cybercrime


Ransomware operators are using a previously undocumented remote-control framework called TukTuk to steal credentials, watch compromised machines, and weaken protections.

The discovery links the tool to activity associated with the Gentlemen ransomware operation and shows how one intrusion can combine access theft, surveillance, and defense evasion.

Its recovery gives defenders an unusual view of the infrastructure and research that can sit behind a ransomware operation.

The framework was recovered from a server holding a malicious DLL sideloading set, EDR-disabling tools, and data believed taken from two large organizations.

That mix suggests a prepared attack environment, able to move from an initial foothold to data theft and ransomware deployment.

It also gives incident responders several distinct traces to investigate. That breadth complicates containment and raises the risk of repeat intrusion. Oasis Security analysts identified the complete TukTuk project, including Windows and Linux agents, a backend, and an operator panel.

EDRKiller and WarsawKiller source files, executables, and the wsftprm.sys driver identified on the server (Source – Oasis Security)

Oasis Security said in a report shared with Cyber Security News (CSN) that the findings also included 224 Jira tickets and eight attachments assessed as exfiltrated from a global technology company, alongside cloud and infrastructure credentials tied to a healthcare organization.

The exposure potentially reaches beyond one victim. The Jira records reportedly included technical information connected with US defense and defense-industry customers, while the healthcare material covered AWS, Azure AD, Bitbucket, production databases, and configuration systems.

The group appears to be gathering information for later access, extortion, or follow-on attacks, increasing the potential cost of a single compromise.

Ransomware Hackers Use New TukTuk Malware

TukTuk is a command-and-control framework that lets an operator manage infected devices from a central panel.

Its Windows agent can collect system details, communicate with the server, run commands, handle files, and capture screens, while the separate Linux agent points to a cross-platform design, which is notable for organizations operating mixed server and workstation estates.

The panel also exposes an especially direct credential-theft option. An operator can trigger a fake Windows Security prompt that resembles the legitimate interface; information entered by the user is then recorded in TukTuk.

This turns a compromised endpoint into a password-collection tool, beyond technical exploits. The discovery follows reporting on GentleKiller ransomware defense evasion, which described the same ransomware ecosystem using vulnerable drivers to shut down endpoint protections.

TukTuk adds a wider control layer for tracking agents, commands, screenshots, and stolen credentials before encryption. Researchers also found a sideloading package using the legitimate Greenshot.exe program and malicious log4net.dll.

In this technique, a trusted application is made to load an attacker-controlled library from its own folder, a pattern also seen in recent DLL sideloading campaigns that hide malicious code behind normal-looking software.

The server contained training material arranged across four lessons on neutralizing EDR products and hunting for vulnerable drivers.

It included eb.sys, a driver whose hash matches a publicly documented GentleKiller sample, plus EDRKiller, WarsawKiller, and UnknownKiller materials. The documents suggest the actors studied how long protections take to recover after process termination.

A vulnerable driver can give attackers deep Windows control, enabling interference with security software before ransomware is launched.

Organizations can reduce that opportunity by enforcing driver allowlisting, enabling Microsoft’s Vulnerable Driver Blocklist, and investigating unexpected driver installations or kernel-level service creation.

Reporting on ransomware EDR killer tactics shows these methods are recurring ransomware tactics. Defenders should also watch for legitimate programs loading unusual nearby DLLs, unexpected credential prompts, and unexplained screen-capture or remote-command behavior.

Sideloading can make a malicious process look routine. The related Mistic credential theft campaign illustrates why endpoint teams should inspect suspicious DLL-to-process relationships rather than relying on file names alone.

Asset and license records (Source - Oasis Security)
Asset and license records (Source – Oasis Security)

Potentially exposed organizations should rotate credentials, review cloud logs, and check Jira-like platforms for secrets and unusually broad downloads.

Teams should block listed indicators, isolate suspected hosts, preserve evidence, and hunt across Windows and Linux environments.

The research group said relevant findings had been shared with affected organizations and institutions. Fast coordination between security, identity, and cloud teams is essential.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
IP address65.109.70.162Server analyzed by researchers; hosted by Hetzner Online in Finland
Domainborjumaniya.storeTukTuk C2 configuration domain identified in the malicious DLL
SHA-25697BD65E98CDC4E93D49EDD4EA905D43A61244DF0FD3323E6649330DE3B1BE091eb.sys hash matching the documented GentleKiller sample
SHA-1138c41085f5f07adbdeff4df97a6a80252571e28Hash of TukTuk.exe
SHA-256e2b31ac7ee077b26332444a83a68ab75be641113e7d86979d844a0f3478f01f9Hash of TukTuk.exe
SHA-256e74088419de2e5b47b1889f2ba1369cb4b436405ce03cf07da452791681f9923Hash of the tuktuk-v2.0_10.zip archive
SHA-256096ec37870eb401793592c9b53b5b52fc7a70b113bc2d9cd3f53231142d6c584Hash of malicious log4net.dll
File nameTukTuk.exeTukTuk operator executable used to access and control the server
File nametuktuk-v2.0_10.zipArchive containing the TukTuk Windows agent, Linux agent, backend, and panel
File namelog4net.dllMalicious DLL sideloaded by the legitimate Greenshot application
File nameGreenshot.exeLegitimate executable abused to load the malicious DLL
File nameeb.sysDriver associated with the GentleKiller EDR-disabling toolset
File namewsftprm.sysDriver found with EDRKiller and WarsawKiller materials
File nameUnknownKiller.exeEDR-neutralization executable found in the training materials
File nameUnKnownKiller.cSource code associated with UnknownKiller
File nameBYOCD_UnkownKiller.mdDocumentation describing driver-based EDR neutralization
File nameLESSON2_EDR_vs_BYOVD.mdMaterial comparing EDR recovery behavior after process termination
File namebd_test_k7old.batVulnerable-driver testing script
File namebd_test_tfsysmon.batVulnerable-driver testing script
File namebd_test_safetica.batVulnerable-driver testing script
File nameDriver_Hunting.mdDocumentation covering vulnerable-driver screening procedures
File name0day_Driver_Research.mdKernel-level driver research material

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.



Click Here For The Original Source.

——————————————————–

..........

.

.