← Back to feed
Breaches & RansomwareEmerging1 sourceMay 11, 2026 · 14:05via The DFIR Report

Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware

Brief

The EtherRAT malware family was first reported by Sysdig back in December 2025. At that time, the initial access vector was exploitation of CVE-2025-55182 (React2Shell) targeting Linux servers. In March 2026, a Windows variant campaign was reported by Atos, with their investigation showing evidence of activity going back to the previous December. In April, we […]

The post Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware appeared first on The DFIR Report .

Read more on The DFIR Report