← Back to Feed
Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware
CVE-2025-55182
May 11, 2026 · DFIR Report · Severity: CRITICAL
The EtherRAT malware family was first reported by Sysdig back in December 2025. At that time, the initial access vector was exploitation of CVE-2025-55182 (React2Shell) targeting Linux servers. In March 2026, a Windows variant campaign was reported by Atos, with their investigation showing evidence of activity going back to the previous December. In April, we […] The post Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware appeared first on The DFIR Report.
Key Takeaways
- Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ran — CRITICAL severity involving CVE-2025-55182
- Security advisory with actionable remediation guidance
- Apply vendor patches and monitor for exploitation activity