TukTuk Malware: Ransomware Operators Steal Credentials

New TukTuk ransomware framework targets credentials and EDR

TukTuk malware has emerged as a new threat in the ransomware landscape, enabling attackers to steal credentials and disable security tools. Recent research links this remote-control framework to the notorious Gentlemen ransomware operation, providing insight into how sophisticated attacks unfold and escalate from initial access to full compromise.

TukTuk Malware: Discovery and Attribution

The TukTuk malware framework was discovered and analysed by Oasis Security, who identified it as a previously undocumented toolkit used by active ransomware groups. The framework came to light when researchers recovered it from a server hosting a collection of hacking tools and stolen data. The infrastructure included DLL sideloading sets, endpoint detection and response (EDR) disabling utilities, and data exfiltrated from at least two large organisations.

Analysis of the recovered files linked TukTuk to activity attributed to the Gentlemen ransomware group. This connection was established through overlapping indicators, toolsets and operational infrastructure. The findings shed light on the strategic planning and layered approach adopted by ransomware operators, moving beyond opportunistic attacks to orchestrated campaigns with well-prepared toolkits.

How TukTuk Malware Works in Ransomware Campaigns

TukTuk functions as a remote-control framework supporting both Windows and Linux environments. Its components include:

  • Malicious DLLs for sideloading and evasion
  • EDR-disabling utilities (notably EDRKiller and WarsawKiller)
  • Operator panel and backend for orchestration
  • Credential theft and data exfiltration modules

Attackers first deploy TukTuk via compromised servers or through phishing and social engineering techniques. Once inside the target environment, the malware establishes persistence and begins to surveil the compromised system. It actively seeks credentials, monitors user activity, and disables local security defences to remain undetected.

The toolkit’s sideloading techniques allow malicious code to masquerade as legitimate software, bypassing application whitelisting and endpoint protections. EDRKiller and WarsawKiller, two utilities found on the same server, are specifically designed to neutralise security software and drivers, giving the attackers unfettered access to the victim network. This capability is critical for ransomware groups, as it paves the way for subsequent data theft and ransomware deployment.

Timeline and Impact: Organisations and Data at Risk

Oasis Security’s investigation revealed that the TukTuk infrastructure was actively used in attacks against at least two major organisations. Evidence from the compromised server included 224 Jira tickets and eight attachments assessed as exfiltrated from a global technology company. Additionally, a cache of cloud and infrastructure credentials linked to a healthcare provider was discovered, suggesting that the attackers targeted sensitive sectors with valuable data.

The timeline for these incidents remains under investigation. However, the presence of multiple toolsets and a fully developed operator panel indicates that the attackers maintained access over an extended period, allowing for thorough reconnaissance and staged operations. The breadth of data collected points to a prepared, end-to-end attack path:

  • Initial compromise using credential theft or exploitation
  • Deployment of TukTuk for surveillance and persistence
  • Disabling of local security measures
  • Exfiltration of sensitive documents and account details
  • Potential ransomware deployment and extortion

Researchers also identified Windows and Linux agents, a backend, and an operator panel within the TukTuk project, underlining its cross-platform reach and scalability. The server infrastructure provided incident responders with multiple avenues for investigation, but also complicated containment and recovery efforts. The attackers’ use of distinct tools and diverse targets increases the risk of repeat intrusions, especially if any traces are missed during initial response.

Current Exploitation Status and Research Insights

As of the latest analysis, there is clear evidence that TukTuk is being used in active ransomware campaigns. The malware’s ability to disable security tools and facilitate credential theft makes it a valuable asset for operators seeking to bypass defences and maximise profit through data theft and extortion. The discovery of exfiltrated data from both a technology company and a healthcare organisation demonstrates that the impact is not theoretical but very real and ongoing.

Oasis Security’s deep dive has provided defenders with rare visibility into the inner workings of a sophisticated ransomware operation. By reverse engineering the TukTuk framework and mapping the infrastructure, researchers have uncovered:

  • Detailed operator workflows and attack stages
  • Cross-platform agent deployment (Windows and Linux)
  • Customised tools for different segments of the attack chain
  • Evidence of long-term access and extensive data collection

This intelligence will help organisations and security vendors develop more effective detection and response strategies for similar threats in the future.

Why TukTuk Malware Matters

The emergence of TukTuk malware highlights the growing sophistication and modularity of ransomware toolkits. The ability to blend credential theft, surveillance, and security tool neutralisation into a single framework raises the stakes for targeted organisations. With evidence of successful attacks against both technology and healthcare sectors, the risk is broad and immediate.

What Organisations Should Do Now

Organisations whose environments include Windows or Linux endpoints should urgently review recent detection logs for signs of DLL sideloading, unexplained credential access, and disabled security software. Proactive monitoring for indicators of compromise linked to TukTuk, EDRKiller, and WarsawKiller may reveal hidden threats. Coordination with incident response experts is recommended for any suspected exposure.

Originally reported by cybersecuritynews.com.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call