DFIR Report – The Gentlemen & SystemBC: A Sneak Peek Behind the Proxy
ID: 78a84eeb-34aa-55cf-8fb7-d8c4ae09a6f5
STIX ID: report--78a84eeb-34aa-55cf-8fb7-d8c4ae09a6f5
Feed Name: Check Point Research
**Executive summary:** The report analyzes "The Gentlemen" RaaS—an active, multi‑platform ransomware affiliate ecosystem (Windows/Linux/ESXi) that has publicly claimed ~320 victims and is associated with SystemBC and a botnet of >1,570 infected hosts; it includes a DFIR timeline, detailed TTPs (credential theft, PsExec/WMI/PsExec/Group Policy mass deployment, Defender/firewall disabling), full technical breakdown of encryption/persistence, and extensive IOCs and a YARA rule for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
