New TukTuk Malware Framework Aids Ransomware Operators in Credential Theft and Evasion
Ransomware operators are employing a new, sophisticated command-and-control framework named TukTuk, designed to steal credentials, conduct surveillance, and disable security tools, according to recent analysis.

Ransomware operators are leveraging a previously undocumented remote-control framework, dubbed TukTuk, to steal credentials, monitor compromised systems, and weaken defensive measures. Discovered by Oasis Security, this framework provides a comprehensive toolkit for attackers, including Windows and Linux agents and a central command-and-control (C2) panel. The findings link the TukTuk framework to activities associated with the Gentlemen ransomware operation, offering a rare glimpse into the infrastructure and research underpinning such attacks.
The TukTuk framework was recovered from a server containing a malicious DLL sideloading set, tools designed to disable endpoint detection and response (EDR) solutions, and data believed to have been exfiltrated from two large organizations. This combination of tools suggests a well-prepared attack environment capable of moving seamlessly from initial compromise to data theft and ransomware deployment. The breadth of capabilities complicates containment efforts and increases the risk of follow-on intrusions.
Oasis Security's analysis revealed the complete TukTuk project, encompassing agents for both Windows and Linux, a backend server, and an operator panel. The Windows agent is capable of collecting system details, communicating with the C2 server, executing commands, managing files, and capturing screenshots. The existence of a separate Linux agent indicates a cross-platform design, a significant consideration for organizations managing mixed server and workstation environments.
A particularly concerning feature of the TukTuk panel is its direct credential-theft capability. Operators can trigger a fake Windows Security prompt that closely mimics the legitimate interface. When users enter their credentials into this fake prompt, the information is captured by TukTuk, effectively turning a compromised endpoint into a powerful password-collection tool beyond traditional exploitation methods.
The discovery of TukTuk follows previous reports on the GentleKiller ransomware's defense evasion tactics, which also involved the use of vulnerable drivers to disable endpoint protections. TukTuk appears to enhance these capabilities by providing a broader control layer for tracking agents, commands, screenshots, and stolen credentials before the final encryption stage of a ransomware attack.
Researchers also identified a sideloading package that abuses the legitimate Greenshot.exe program by loading a malicious log4net.dll. This technique, where a trusted application loads an attacker-controlled library, is a common method used in recent DLL sideloading campaigns to disguise malicious code within seemingly normal software.
The server also contained training materials focused on neutralizing EDR products and identifying vulnerable drivers. These materials suggest the actors deliberately studied how security protections recover after process termination. The use of vulnerable drivers grants attackers deep control within Windows, allowing them to interfere with security software before launching ransomware. Organizations can mitigate this risk by enforcing driver allowlisting, enabling Microsoft’s Vulnerable Driver Blocklist, and monitoring for unusual driver installations or kernel-level service creation.
The exfiltrated data from the compromised organizations included sensitive technical details and cloud credentials. Specifically, 224 Jira tickets potentially linked to US defense and defense-industry customers were found, alongside cloud and infrastructure credentials for a healthcare organization, including AWS, Azure AD, Bitbucket, and production database access. This exposure highlights the potential for widespread impact beyond the immediate victims, as the gathered information could be used for further extortion or follow-on attacks.