logo

Gentlemen RaaS Attacking Windows, Linux With additional locker written in C for ESXi

ID: d0febb92-9604-5a05-8e75-88ca4db52643

STIX ID: report--d0febb92-9604-5a05-8e75-88ca4db52643

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-04-21

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

The report describes a high-risk RaaS operation named "The Gentlemen" active since mid-2025 that rapidly expanded to hundreds of victims and a global botnet (telemetry shows ~1,570 infected hosts). The group offers cross-platform ransomware (Go-based lockers for Windows/Linux/NAS/BSD and a C-based ESXi locker), recruits affiliates, and uses SystemBC and Cobalt Strike for foothold and lateral movement, employing techniques such as disabling Windows Defender, adding broad exclusions, deleting shadow copies, abusing GPOs to deploy payloads, and publishing victim data on a dark web leak site; recommended mitigations include enforcing MFA for administrative accounts, network segmentation, tamper-resistant endpoint protections and firewalls, isolating backups, and monitoring for lateral movement and unusual scheduled tasks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.