← Back to Feed

Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware

CVE-2025-55182

May 11, 2026 · DFIR Report · Severity: CRITICAL

The DFIR Report's flash alert details EtherRAT, a malware family first reported by Sysdig after exploitation of CVE-2025-55182 against Linux servers. Later campaigns used a Windows variant, with evidence extending back to December 2025. The attack flow concludes with The Gentleman ransomware, indicating a coordinated progression from initial access to encryption.

Key Takeaways

  • EtherRAT initially targeted Linux servers through CVE-2025-55182 exploitation.
  • A Windows variant campaign emerged in March 2026, active since December 2025.
  • The infection chain ultimately leads to The Gentleman ransomware deployment.
☕ Buy a Coffee