Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware

2026-05-11T20:52:04Z14804b1095c95902c568da9e6fefaf2aa5aaf15dc5fe665d15e87a9bcd7d0b2e
AI-assisted operationsAkiraApache ActiveMQBissa scannerBumblebeeClaude CodeELPACO-teamEtherRATInterlock RATKongTukeLockBitLunar SpiderLynx ransomwareOpenClawRDP password sprayRansomHubSEO poisoningThe Gentleman ransomwareTukTukcredential harvestingmass exploitationremote code executiontemplate injectionthreat actor tooling

What happened

The DFIR Report collection highlights multiple recent intrusion and ransomware campaigns: EtherRAT (including a Windows variant) and TukTuk C2 activity culminating in The Gentleman ransomware; an AI-assisted mass-exploitation/credential-harvesting platform (Bissa scanner) leveraging Claude Code/OpenClaw; an Apache ActiveMQ RCE chain that led to LockBit deployment; exploitation of unpatched Confluence (template injection) resulting in ELPACO-team ransomware; RDP password-spray access leading to RansomHub; and discovery of a new PHP-based Interlock RAT variant (KongTuke/FileFix). Common initial‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
thedfirreport
Record identifier
14804b1095c95902c568da9e6fefaf2aa5aaf15dc5fe665d15e87a9bcd7d0b2e
Enrichment time
2026-05-11T20:52:04Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.