A detailed flash alert from The DFIR Report covering an April 2026 intrusion chain starting with EtherRAT delivered via a malicious MSI disguised as Sysinternals RAMMap. EtherRAT used Ethereum blockchain (EtherHiding) for dynamic C2 resolution via 1rpc.io. The threat actor later deployed TukTuk, an AI-generated malware framework using DLL sideloading via trojanized Greenshot, SyncTrayzor, DocFX, and Cake binaries, with C2 channels over SaaS platforms (ClickHouse, Supabase, Ably, Dropbox, GitHub Issues) and Arweave blockchain as a dead-drop resolver. Post-compromise activity included Kerberoasting, LSASS/NTDS dumping, Mimikatz, NetExec lateral movement, GoTo Resolve RMM deployment, and Rclone-based data exfiltration to Wasabi cloud storage. The intrusion culminated in domain-wide deployment of The Gentlemen ransomware via a malicious GPO. Detection guidance, IOCs, Sigma-style hunt queries, and ET OPEN rules are provided.