← Back to Feed

Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware

CVE-2025-55182

May 11, 2026 · DFIR Report · Severity: CRITICAL

The EtherRAT malware family was first reported by Sysdig back in December 2025.

Key Takeaways

  • At that time, the initial access vector was exploitation of CVE-2025-55182 (React2Shell) targeting Linux servers. The EtherRAT malware family was first reported by Sysdig back in December 2025.
  • In April, we […] The post Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware appeared first.
☕ Buy a Coffee