RansomwareThe DFIR Report·3 months ago
Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware
EtherRAT malware, which emerged in December 2025 with initial Linux exploitation via CVE-2025-55182, evolved to target Windows systems by March 2026 with activity traceable back to its discovery. The threat culminated in April when EtherRAT and TukTuk C2 infrastructure were leveraged in campaigns deploying The Gentleman ransomware. This progression demonstrates the rapid weaponization and expansion of the malware family across multiple platforms and attack stages.