Ransomware Group Targets Fortinet and Cisco Devices To Breach Networks
ID: 6acec42f-1f59-57c5-bb5b-31b469271c5a
STIX ID: report--6acec42f-1f59-57c5-bb5b-31b469271c5a
Feed Name: Cyber Press
**The Gentlemen RaaS** has rapidly expanded since mid-2025 into a high-volume ransomware operation, publishing hundreds of victims and with research revealing over a thousand compromised corporate environments and tens of thousands of abused edge devices (notably FortiGate). Leaked internal chats and an exposed database detail an affiliate-driven profit model, double-extortion extortion, credential brute-forcing and exploitation of public-facing vulnerabilities, and a mature toolset (NetExec, SystemBC, Velociraptor, DumpBrowserSecrets) used to exfiltrate data and deploy multi-OS lockers across critical sectors including healthcare, energy, and manufacturing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
