logo

Exposed Server Reveals TheGentlemen Ransomware Toolkit, Victim Credentials, and Ngrok Tokens

ID: ea986f76-520b-5ce6-a9a7-6a8a4450daeb

STIX ID: report--ea986f76-520b-5ce6-a9a7-6a8a4450daeb

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-03-30

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A misconfigured server on a Russian bulletproof hosting provider exposed ~140 MB of operational material from a TheGentlemen ransomware affiliate, including harvested credentials, plaintext authentication tokens, and a highly destructive pre-encryption batch script (z1.bat) that disables security products, deletes backups and logs, creates open SMB shares, and establishes persistence; analysts identified the server at 176.120.22.127 and recommend blocking the IP, monitoring for ngrok tunnels and Mimikatz-like activity, and hardening endpoints and backup protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.