TukTuk showed up later in the intrusion as a SaaS-heavy malware framework. We observed TukTuk variants disguised as legitimate tools, executed through DLL sideloading, and using platforms like ClickHo
TukTuk showed up later in the intrusion as a SaaS-heavy malware framework. We observed TukTuk variants disguised as legitimate tools, executed through DLL sideloading, and using platforms like ClickHouse and Supabase for C2, with multiple backup transports available. Full report: https:// thedfirreport.com/2026/05/11/f lash-alert-etherrat-and-tuktuk-c2-end-in-the-gentleman-ransomware/ # DFIR # Thr