← Threat Actors & APT Groups

The Gentleman

Every article that identifies The Gentleman as responsible for or connected to reported activity.

RansomwareThe DFIR Report·3 months ago

Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware

EtherRAT malware, which emerged in December 2025 with initial Linux exploitation via CVE-2025-55182, evolved to target Windows systems by March 2026 with activity traceable back to its discovery. The threat culminated in April when EtherRAT and TukTuk C2 infrastructure were leveraged in campaigns deploying The Gentleman ransomware. This progression demonstrates the rapid weaponization and expansion of the malware family across multiple platforms and attack stages.