← Back to Feed
Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware
CVE-2025-55182
May 11, 2026 · DFIR Report · Severity: CRITICAL
The DFIR Report's flash alert details EtherRAT, a malware family first reported by Sysdig after exploitation of CVE-2025-55182 against Linux servers. Later campaigns used a Windows variant, with evidence extending back to December 2025. The attack flow concludes with The Gentleman ransomware, indicating a coordinated progression from initial access to encryption.
Key Takeaways
- EtherRAT initially targeted Linux servers through CVE-2025-55182 exploitation.
- A Windows variant campaign emerged in March 2026, active since December 2025.
- The infection chain ultimately leads to The Gentleman ransomware deployment.