Hermes CTI

← Back to all reports

vulnerability new

CVE-2025-55182

● MEDIUM Confidence: 90% · Version 1

Executive summary

Public evidence documents CVE-2025-55182. This report does not assess any organization.

Technical analysis

Cloud attack framework skips cryptomining, harvests financial, messaging, and enterprise credentials for fraud, spam, and potential extortion.

Evidence and sources

Public evidence for CVE-2025-55182 with preserved provenance.

Verified Evidence Claims

CVE-2025-55182 PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale Cloud attack framework skips cryptomining, harvests financial, messaging, and enterprise credentials for fraud, spam, and potential extortion.

Attribution: SentinelLabs
100% Confidence Analysis 🔍

CVE-2025-55182 Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware The EtherRAT malware family was first reported by Sysdig back in December 2025. At that time, the initial access vector was exploitation of CVE-2025-55182 (React2Shell) targeting Linux servers. In March 2026, a Windows variant campaign was reported by Atos, with their investigation showing evidence of activity going back to the previous December. In April, we […] The post Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware appeared first on The DFIR Report.

Attribution: The DFIR Report
100% Confidence Analysis 🔍

IOCs

No public IOC is available.

CVEs and affected products

PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale

ATT&CK mapping

No ATT&CK mapping is available.

Detection content

Sigma rules, YARA rules, Splunk SPL, and KQL detection logic.

Open dedicated detections page →

Threat hunting

Hypothesis-driven hunt procedures and telemetry checklist.

Open dedicated hunt page →

Remediation

Containment actions, patching notes, and credential steps.

Open dedicated remediation page →

Historical relationships

No published historical relationship is available.

Timeline and change history

Public source record: Public source record for CVE-2025-55182.

Confidence and caveats

0.9

⚠️ Public CTI only; no organizational exposure is asserted.

⚠️ CVSS and EPSS metadata were not present in the retrieved evidence payload.