Ransomware Hackers Use New TukTuk Malware to Steal Credentials and Disable Security Tools
Brief
Ransomware operators are using a previously undocumented remote-control framework called TukTuk to steal credentials, watch compromised machines, and weaken protections.
The discovery links the tool to activity associated with the Gentlemen ransomware operation and shows how one intrusion can combine access theft, surveillance, and defense evasion.
Its recovery gives defenders an unusual view of the infrastructure and research that can sit behind a ransomware operation.
The framework was recovered from a server holding a malicious DLL sideloading set, EDR-disabling tools, and data believed taken from two large organizations.
That mix suggests a prepared attack environment, able to move from an initial foothold to data theft and ransomware deployment.
It also gives incident responders several distinct traces to investigate.
