Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Inside The Gentlemen: Undisclosed TukTuk C2 Framework and EDR Neutralization Research

0
Medium
Published: 09/02/2026 (09/02/2026, 18:24:11 UTC)
Source: AlienVault OTX General

Description

Analysis of server infrastructure revealed a complete TukTuk C2 framework (version 2.0) with cross-platform capabilities, including Windows and Linux agents, backend infrastructure, and management panel. The server contained eb.sys matching GentleKiller, along with comprehensive EDR neutralization training materials organized in four progressive lessons covering BYOVD techniques, vulnerable driver hunting, and kernel-level research. DLL sideloading configurations targeting Greenshot, ProcMon, Slack, and Postman were identified. Exfiltrated data included 224 Jira tickets from a global technology company containing information related to U.S. defense organizations and defense contractors, plus credentials from a global healthcare company's Infrastructure-as-Code platform exposing AWS keys, production databases, Azure AD, and Bitbucket access.

Technical Details

Author
AlienVault
Tlp
white
References
["https://oasis-security.io/blog/The-Gentlemen-Ransomware-Hacker-Groups-TukTuk-Framework"]
Adversary
The Gentlemen
Pulse Id
6a9869cb21bbf3f757424b7f
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainborjumaniya.store

Hash

ValueDescriptionCopy
hash4e5136230ec590ce6ef038aac6e72cb2
hashba914fe77b177b45799403b16dd14765c510a074
hash97bd65e98cdc4e93d49edd4ea905d43a61244df0fd3323e6649330de3b1be091
hash138c41085f5f07adbdeff4df97a6a80252571e28
hashe2b31ac7ee077b26332444a83a68ab75be641113e7d86979d844a0f3478f01f9
hashe74088419de2e5b47b1889f2ba1369cb4b436405ce03cf07da452791681f9923
hash096ec37870eb401793592c9b53b5b52fc7a70b113bc2d9cd3f53231142d6c584
hash07f74b7d16181dec1401c85f8ebe45f3
hash4294c1e975d80fdedfa29919035e5efb
hash7c17c2bdd8d8efffb26be64245b08a22febb3cf9

Threat ID: 6a992751acd9273b49a066e3

Added to database: 09/03/2026, 07:52:49 UTC

Last updated: 09/03/2026, 13:14:38 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses