Hermes CTI

← Back to all reports

threat updated

Analysis of Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware

● CRITICAL Confidence: 95% · Version 2

Executive summary

Technical threat analysis derived from intelligence published at https://thedfirreport.com/2026/05/11/flash-alert-etherrat-and-tuktuk-c2-end-in-the-gentleman-ransomware/. Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware The EtherRAT malware family was first reported by Sysdig back in December 2025. At that time, the initial access vector was exploitation of CVE-2025-55182 (React2Shell) targeting Linux servers. In March 2026, a Windows variant campaign was reported by Atos, with their investigation showing evidence of activity going back to the previous December. In April, we […] The post Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware appeared first on The DFIR Report.

Technical analysis

Technical threat analysis derived from intelligence published at https://thedfirreport.com/2026/05/11/flash-alert-etherrat-and-tuktuk-c2-end-in-the-gentleman-ransomware/. Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware The EtherRAT malware family was first reported by Sysdig back in December 2025. At that time, the initial access vector was exploitation of CVE-2025-55182 (React2Shell) targeting Linux servers. In March 2026, a Windows variant campaign was reported by Atos, with their investigation showing evidence of activity going back to the previous December. In April, we […] The post Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware appeared first on The DFIR Report.

Evidence and sources

Analysis of Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware. The EtherRAT malware family was first reported by Sysdig back in December 2025. At that time, the initial access vector was exploitation of CVE-2025-55182 (React2Shell) targeting Linux servers. In March 2026, a Windows variant campaign was reported by Atos, with their investigation showing evidence of activity going back to the previous December. In April, we […] The post Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware appeared first on The DFIR Report.. Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware The EtherRAT malware family was first reported by Sysdig back in December 2025. At that time, the initial access vector was exploitation of CVE-2025-55182 (React2Shell) targeting Linux servers. In March 2026, a Windows variant campaign was reported by Atos, with their investigation showing evidence of activity going back to the previous December. In April, we […] The post Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware appeared first on The DFIR Report.

Authoritative Source Advisories
Verified Evidence Claims

Analysis of Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware. The EtherRAT malware family was first reported by Sysdig back in December 2025. At that time, the initial access vector was exploitation of CVE-2025-55182 (React2Shell) targeting Linux servers. In March 2026, a Windows variant campaign was reported by Atos, with their investigation showing evidence of activity going back to the previous December. In April, we […] The post Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware appeared first on The DFIR Report.. Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware The EtherRAT malware family was first reported by Sysdig back in December 2025. At that time, the initial access vector was exploitation of CVE-2025-55182 (React2Shell) targeting Linux servers. In March 2026, a Windows variant campaign was reported by Atos, with their investigation showing evidence of activity going back to the previous December. In April, we […] The post Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware appeared first on The DFIR Report.

95% Confidence Analysis 🔍

IOCs

No public IOC is available.

CVEs and affected products

No CVE or affected product is available.

ATT&CK mapping

No ATT&CK mapping is available.

Detection content

Sigma rules, YARA rules, Splunk SPL, and KQL detection logic.

Open dedicated detections page →

Threat hunting

Hypothesis-driven hunt procedures and telemetry checklist.

Open dedicated hunt page →

Remediation

Containment actions, patching notes, and credential steps.

Open dedicated remediation page →

Historical relationships

No published historical relationship is available.

Timeline and change history

Threat Intelligence Publication: Public advisory published: Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware

Confidence and caveats

0.95

⚠️ This report describes public threat intelligence only and makes no assertion regarding internal organizational exposure.