← Back to feed
Breaches & RansomwareEmerging1 sourceSep 2, 2026 · 08:06via CyberPress

Ransomware Hackers Built Their Own C2 Framework to Steal Passwords and Kill Security Tools

Brief

A newly analyzed server linked to the ransomware group The Gentlemen contained a previously undocumented command-and-control (C2) framework called TukTuk, tools designed to disable endpoint security products, and data believed to have been stolen from two global companies.

Threat intelligence researchers identified the server at IP address 65.

  • 70. 162, hosted by Hetzner Online in Finland.

The collected files included the full TukTuk C2 project, malicious DLL sideloading components, EDR-killing tools, vulnerable-driver research, and exfiltrated corporate information.

Researchers said the evidence connects the infrastructure to The Gentlemen ransomware operation. One major indicator was an eb. sys file whose hash matched GentleKiller, a driver previously associated with the group.

Read more on CyberPress