CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 575

As cited

Copy frozen at (site build).

ransomware

Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware

EtherRAT malware, initially discovered in December 2025 targeting Linux servers via CVE-2025-55182, evolved to include a Windows variant by March 2026. Recent findings indicate that EtherRAT and TukTuk command and control infrastructure have been repurposed or connected to The Gentleman ransomware operations.

Why it matters: Organizations running Linux and Windows servers need to assess whether they were targeted by EtherRAT campaigns and patch CVE-2025-55182, as compromised systems may now face ransomware deployment by The Gentleman threat group.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware

EtherRAT malware, initially discovered in December 2025 targeting Linux servers via CVE-2025-55182, evolved to include a Windows variant by March 2026. Recent findings indicate that EtherRAT and TukTuk command and control infrastructure have been repurposed or connected to The Gentleman ransomware operations.

Why it matters: Organizations running Linux and Windows servers need to assess whether they were targeted by EtherRAT campaigns and patch CVE-2025-55182, as compromised systems may now face ransomware deployment by The Gentleman threat group.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary