Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware

2026-06-16T20:51:50Za3f1375e2811cc3a8aa7dabacba92babb45caf9b4eeb7e58d7c219882276c8fa
AI-assisted exploitationAkiraApache ActiveMQBissa scannerBumblebeeCVE-2023-22527CVE-2023-46604Claude CodeConfluenceELPACO-teamEtherRATInterlock RATKongTuke FileFixLockBitLunar SpiderLynx ransomwareOpenClawRDPRansomHubThe Gentleman ransomwareTukTukcredential harvestinginitial access exploitsmass exploitationpassword spray

What happened

The DFIR Report feed summarizes multiple recent intrusion and malware campaigns: EtherRAT (including a Windows variant) and TukTuk C2 activity culminating in The Gentleman ransomware (initial Linux access tied to CVE-2025-55182/React2Shell); an exposed Bissa scanner used for AI-assisted mass exploitation and credential harvesting; an Apache ActiveMQ RCE exploitation (CVE-2023-46604) leading to LockBit ransomware; RDP-based intrusions and password-spray attacks delivering RansomHub and Lynx ransomware; SEO/SEO-poisoning and Bumblebee delivering Akira; a new PHP-based Interlock RAT variant; and,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
thedfirreport
Record identifier
a3f1375e2811cc3a8aa7dabacba92babb45caf9b4eeb7e58d7c219882276c8fa
Enrichment time
2026-06-16T20:51:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.