Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware

Reported 11 May 2026 by otx · Severity: medium

An intrusion was observed in April 2026 where threat actors deployed EtherRAT malware through a malicious MSI installer disguised as a Sysinternals tool. The malware utilized Ethereum blockchain via EtherHiding for dynamic C2 configuration updates. Following reconnaissance activi