Minacce · 160 giorni fa
The Gentlemen is built for broad disruption, not just file encryption. Its affiliates get lockers for Windows, Linux, NAS, BSD, and ESXi, plus EDR-killing tools and pivot infrastructure that can move inside a victim network and reach virtualized systems that hold many workloads at once.
Check Point says the group emerged around mid-2025 and has already publicly claimed a little over 320 victims, with most infections in 2026. It recruits affiliates on underground forums, uses Tox for negotiations, and runs an onion leak site and public social account to pressure victims who refuse to pay.
The practical risk is a ransomware operation that can hit mixed estates and hypervisors from one affiliate playbook. That makes datacenter availability the target, not just endpoint recovery, and it raises the odds that a single intrusion can spread across Windows hosts, NAS devices, and ESXi infrastructure.
5 fonti che coprono questa storia
'The Gentlemen' Rapidly Rises to Ransomware Prominence
Not nearly as polite as the name suggests, the ransomware gang has impressed researchers with its speed in scaling up operations — and its sophistication.
SystemBC C2 Server Reveals 1,570+ Victims in The Gentlemen Ransomware Operation
SystemBC C2 exposed 1,570+ victims tied to The Gentlemen since July 2025, revealing expanding ransomware scale.
Surge in Bomgar RMM Exploitation Demonstrates Supply Chain Risk
The critical remote code execution flaw (CVE-2026-1731) in the remote monitoring and management tool can be exploited to spread ransomware.
The Gentlemen Ransomware Expands With Rapid Affiliate Growth
Gentlemen RaaS expands quickly with multi-platform attacks and SystemBC-linked infections
The Gentlemen ransomware now uses SystemBC for bot-powered attacks
A SystemBC proxy malware botnet of more than 1,570 hosts, believed to be corporate victims, has been discovered following an investigation into a Gentlemen ransomware attack carried out by a gang affiliate.
DFIR Report – The Gentlemen & SystemBC: A Sneak Peek Behind the Proxy - Check Point Research
The RaaS provides affiliates with multi‑OS lockers for Windows, Linux, […
Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-04-21