The Gentlemen RaaS Surges as Bomgar CVE-2026-1731 Exploited

Research shows The Gentlemen ransomware-as-a-service operation rapidly expanded, claiming 320+ victims and leveraging cross-platform Go-based encryptors, an ESXi encryptor, and SystemBC proxy malware in affiliate-supported intrusions. Separately, Huntress and others report an active uptick in exploitation of a critical unauthenticated RCE (CVE-2026-1731) in Bomgar/BeyondTrust Remote Support and older PRA, which attackers are using to spread ransomware and compromise supply chains.

Part of the PlainSec briefing for 2026-04-21

Sources