← Back to Feed
Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware
CVE-2025-55182
May 11, 2026 · DFIR Report · Severity: CRITICAL
This DFIR flash alert analyzes the EtherRAT malware family, which began with Linux exploitation via CVE-2025-55182. A Windows variant campaign was later reported, with activity dating back to the prior December. Researchers observed the use of TukTuk command-and-control infrastructure leading to The Gentleman ransomware.
Key Takeaways
- EtherRAT's initial vector was exploitation of React2Shell CVE-2025-55182 on Linux.
- Windows variant activity was documented by Atos in March 2026.
- The campaign ends with The Gentleman ransomware after EtherRat and TukTuk C2.