Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware
2026-05-11T20:52:04Z•14804b1095c95902c568da9e6fefaf2aa5aaf15dc5fe665d15e87a9bcd7d0b2e
AI-assisted operationsAkiraApache ActiveMQBissa scannerBumblebeeClaude CodeELPACO-teamEtherRATInterlock RATKongTukeLockBitLunar SpiderLynx ransomwareOpenClawRDP password sprayRansomHubSEO poisoningThe Gentleman ransomwareTukTukcredential harvestingmass exploitationremote code executiontemplate injectionthreat actor tooling
What happened
The DFIR Report collection highlights multiple recent intrusion and ransomware campaigns: EtherRAT (including a Windows variant) and TukTuk C2 activity culminating in The Gentleman ransomware; an AI-assisted mass-exploitation/credential-harvesting platform (Bissa scanner) leveraging Claude Code/OpenClaw; an Apache ActiveMQ RCE chain that led to LockBit deployment; exploitation of unpatched Confluence (template injection) resulting in ELPACO-team ransomware; RDP password-spray access leading to RansomHub; and discovery of a new PHP-based Interlock RAT variant (KongTuke/FileFix). Common initial‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- thedfirreport
- Record identifier
- 14804b1095c95902c568da9e6fefaf2aa5aaf15dc5fe665d15e87a9bcd7d0b2e
- Enrichment time
- 2026-05-11T20:52:04Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.