← Back to Feed
Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware
CVE-2025-55182
May 11, 2026 · DFIR Report · Severity: CRITICAL
The EtherRAT malware family was first reported by Sysdig back in December 2025.
Key Takeaways
- At that time, the initial access vector was exploitation of CVE-2025-55182 (React2Shell) targeting Linux servers. The EtherRAT malware family was first reported by Sysdig back in December 2025.
- In April, we […] The post Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware appeared first.