How The Gentlemen Ransomware Group Operates: A Blueprint Built on Infostealer Credentials
ID: f7dd5132-199e-5d0c-81a8-c547d2bff5e8
STIX ID: report--f7dd5132-199e-5d0c-81a8-c547d2bff5e8
Feed Name: infostealers.com
Threat Score
An internal leak from The Gentlemen RaaS exposes their operational blueprint: rather than relying on zero-days, affiliates heavily exploit aggregated infostealer credential logs (via services like Snusbase) to gain initial access, pivot internally, and conduct extortion; the report links this modus operandi to broader trends (e.g., the Coinbase Cartel) and recommends prioritizing infostealer monitoring to prevent credential-based compromises.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
