← Back to Feed

Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware

CVE-2025-55182

May 11, 2026 · DFIR Report · Severity: CRITICAL

This DFIR flash alert analyzes the EtherRAT malware family, which began with Linux exploitation via CVE-2025-55182. A Windows variant campaign was later reported, with activity dating back to the prior December. Researchers observed the use of TukTuk command-and-control infrastructure leading to The Gentleman ransomware.

Key Takeaways

  • EtherRAT's initial vector was exploitation of React2Shell CVE-2025-55182 on Linux.
  • Windows variant activity was documented by Atos in March 2026.
  • The campaign ends with The Gentleman ransomware after EtherRat and TukTuk C2.
☕ Buy a Coffee