logo

GENTLEMEN RANSOMWARE LEAKS

ID: d007b8f4-fe5c-53f2-be53-4f6151fadb6b

STIX ID: report--d007b8f4-fe5c-53f2-be53-4f6151fadb6b

Feed Name: THE RAVEN FILE

Threat Score
80/100

Date Published: 2026-05-23

Date Updated: 2026-05-23

Author: RakeshKrish

...
...

The report analyzes a May 2026 leak from the Gentlemen ransomware group (420+ victims reported), detailing their primary TTPs (FortiGate SSL‑VPN panel brute‑force/config theft, LDAP abuse, SSL‑VPN tunnels), exfiltration tooling (MEGAcmd, rclone, MEGA hosting), operator infrastructure (Synology NAS staging, Russian-hosted IPs), victim artifacts (Windows DC backup XMLs, Proxmox backups), and operational issues (EDR interference, encryption problems), concluding the group operates as a RaaS using widely available tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.