Exposed Server Reveals TheGentlemen Ransomware Toolkit, Victim Credentials, and Ngrok Tokens
ID: ea986f76-520b-5ce6-a9a7-6a8a4450daeb
STIX ID: report--ea986f76-520b-5ce6-a9a7-6a8a4450daeb
Feed Name: cybersecurityNews.com
A misconfigured server on a Russian bulletproof hosting provider exposed ~140 MB of operational material from a TheGentlemen ransomware affiliate, including harvested credentials, plaintext authentication tokens, and a highly destructive pre-encryption batch script (z1.bat) that disables security products, deletes backups and logs, creates open SMB shares, and establishes persistence; analysts identified the server at 176.120.22.127 and recommend blocking the IP, monitoring for ngrok tunnels and Mimikatz-like activity, and hardening endpoints and backup protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
