logo

Ransomware Group Targets Fortinet and Cisco Devices To Breach Networks

ID: 6acec42f-1f59-57c5-bb5b-31b469271c5a

STIX ID: report--6acec42f-1f59-57c5-bb5b-31b469271c5a

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Varshini

...
...

**The Gentlemen RaaS** has rapidly expanded since mid-2025 into a high-volume ransomware operation, publishing hundreds of victims and with research revealing over a thousand compromised corporate environments and tens of thousands of abused edge devices (notably FortiGate). Leaked internal chats and an exposed database detail an affiliate-driven profit model, double-extortion extortion, credential brute-forcing and exploitation of public-facing vulnerabilities, and a mature toolset (NetExec, SystemBC, Velociraptor, DumpBrowserSecrets) used to exfiltrate data and deploy multi-OS lockers across critical sectors including healthcare, energy, and manufacturing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.