TukTuk showed up later in the intrusion as a SaaS-heavy malware framework. We observed TukTuk variants disguised as legitimate tools, executed through DLL sideloading, and using platforms like ClickHo

TukTuk showed up later in the intrusion as a SaaS-heavy malware framework. We observed TukTuk variants disguised as legitimate tools, executed through DLL sideloading, and using platforms like ClickHouse and Supabase for C2, with multiple backup transports available. Full report: https:// thedfirreport.com/2026/05/11/f lash-alert-etherrat-and-tuktuk-c2-end-in-the-gentleman-ransomware/ # DFIR # Thr

1 reportother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

TukTuk showed up later in the intrusion as a SaaS-heavy malware framework. We observed TukTuk variants disguised as legitimate tools, executed through DLL sideloading, and using platforms like ClickHo

mastodon:infosec-exchangeother14d ago kagi ↗

TukTuk showed up later in the intrusion as a SaaS-heavy malware framework. We observed TukTuk variants disguised as legitimate tools, executed through DLL sideloading, and using platforms like ClickHouse and Supabase for C2, with multiple backup transports available. Full report: https:// thedfirreport.com/2026/05/11/f lash-alert-etherrat-and-tuktuk-c2-end-in-the-gentleman-ransomware/ # DFIR # Thr