A server tied to The Gentlemen exposed TukTuk C2, a credential-stealing prompt, EDR-killer research, exfiltrated Jira data, and healthcare credentials.2026-09-04T10:46:43.199Z4 min2026threatsendpointidentity
4 min read
Read format

Ransomware Server Exposes Credential Theft and EDR-Killer Toolkit

A server tied to The Gentlemen exposed TukTuk C2, a credential-stealing prompt, EDR-killer research, exfiltrated Jira data, and healthcare credentials.

By Justin Howe
An opened rack server on a forensic bench has one drive tray pulled forward for examination.

A server associated with The Gentlemen ransomware operation exposed a complete, previously undocumented command-and-control project beside endpoint-defense killers, Jira data assessed as stolen from a technology company, and credentials tied to a healthcare company. The collection gives defenders a rare view of the tooling, research, and potential victim material gathered in one place.

Oasis Security’s Threat Intelligence Unit found the server through its AGATHA intelligence service. Researchers said the complete TukTuk project had “no prior public disclosure or documentation” they could confirm. They also found 224 Jira tickets and eight attachments assessed as exfiltrated from a technology company, plus credentials and infrastructure information associated with a healthcare company’s infrastructure-as-code platform.

A single server joined three layers

The server at 65[.]109[.]70[.]162 held attack tooling, research material, and possible victim data. The attack layer included TukTuk.exe, the full tuktuk-v2.0_10.zip project, a Greenshot DLL side-loading set, and the files eb.sys, EDRKiller, WarsawKiller, UnknownKiller, and wsftprm.sys.

The research layer was organized into four lessons. Files included UnKnownKiller.c, UnknownKiller.exe, BYOCD_UnkownKiller.md, LESSON2_EDR_vs_BYOVD.md, bd_test_k7old.bat, bd_test_tfsysmon.bat, bd_test_safetica.bat, Driver_Hunting.md, and 0day_Driver_Research.md. Oasis said the sequence moved from studying EDR-killer behavior to testing vulnerable drivers and researching kernel techniques.

The data layer was different. A jira-loot folder held the tickets and attachments, including support records tied to US defense and defense-industry customers. Separate healthcare material included administrator-level AWS access information, production database credentials, Azure AD, Bitbucket, cloud storage, and infrastructure configuration data. Oasis shared its findings with affected organizations and institutions, but published no responses.

Three evidence layers from one server connect TukTuk remote control, endpoint-defense research, and assessed enterprise data theft.

Long description

The diagram starts with one analyzed server and branches into three evidence layers. The first contains the TukTuk Windows agent, Linux agent, backend, Electron panel, and their remote-control functions. The second contains the Greenshot side-loading set, EDR-killer files, and four stages of vulnerable-driver research. The third contains 224 Jira tickets, eight attachments, and healthcare infrastructure credentials. A note separates direct file observations from Oasis Security’s attribution and exfiltration assessments.

TukTuk controlled Windows and Linux

The recovered archive contained four main directories: agent, agent-linux, backend, and panel. Its Windows agent collected system information, polled for commands, handled files, captured screens, and opened shell sessions. The separate Linux agent used the same polling idea, while the backend tracked agents, delivered commands, and received results.

The Electron panel brought those functions together. Operators could view compromised hosts, control processes, upload files, request screenshots, and execute arbitrary Windows commands. Its most vivid feature was a credential prompt that imitated Windows Security. Entries supplied by a user were recorded in TukTuk’s credential view.

The legitimate Greenshot.exe program provided an execution path for the malicious log4net.dll placed beside it. Static analysis of that DLL revealed TukTuk code, server settings, tokens, and the domain borjumaniya[.]store. It also referenced the legitimate shared services slack.com, github.com, and dropbox.com, among other settings. Those services are normal platforms; the report describes their settings inside malicious configuration rather than treating the platforms as hostile infrastructure.

Recovered files expose recognition clues

Defenders can search retained endpoint, network, and file telemetry for this combined set before deciding that a single hash match proves an incident. Start with connections to 65[.]109[.]70[.]162 or borjumaniya[.]store, then correlate them with TukTuk.exe, tuktuk-v2.0_10.zip, the Greenshot.exe plus log4net.dll side-loading pair, or the recovered EDR-killer names.

Oasis published five high-value hashes:

  • eb.sys SHA-256: 97BD65E98CDC4E93D49EDD4EA905D43A61244DF0FD3323E6649330DE3B1BE091
  • TukTuk.exe SHA-1: 138c41085f5f07adbdeff4df97a6a80252571e28
  • TukTuk.exe SHA-256: e2b31ac7ee077b26332444a83a68ab75be641113e7d86979d844a0f3478f01f9
  • tuktuk-v2.0_10.zip SHA-256: e74088419de2e5b47b1889f2ba1369cb4b436405ce03cf07da452791681f9923
  • Malicious log4net.dll SHA-256: 096ec37870eb401793592c9b53b5b52fc7a70b113bc2d9cd3f53231142d6c584

The attribution case used relationships as well as hashes. The eb.sys sample matched the GentleKiller driver by SHA-256. The greenshot_sideload folder paired the legitimate executable with the malicious DLL. A dashboard screenshot showed hostname DESKTOP-22EVPBQ and operator identifier Neo, which matched earlier public reporting on The Gentlemen.

Evidence sets a narrow boundary

The files establish what was stored on one server. They do not establish how many hosts ran TukTuk, whether every research file reached an operation, or whether all recovered credentials remained valid. Oasis describes the Jira material as exfiltrated and the server’s ownership as an attribution assessment, so those conclusions should retain that qualification.

Recognition is the immediate defender advantage. Preserve hits with their parent process, file path, signer, creation time, network destination, user context, and surrounding authentication activity. A hash on its own can identify a published sample; the side-loading pair, C2 destination, credential-prompt behavior, or related EDR-killer files can show whether the match belongs to an intrusion sequence.

The report supplies no complete containment procedure or recovery test. That gap makes the evidence set more valuable as a scoping tool: it can identify which hosts and identities deserve deeper incident response while affected organizations establish their own clean-state criteria from retained telemetry.

Primary sources

Continue reading

Article figurePinch or double-tap to zoom, then drag to pan.