logo

DFIR Report – The Gentlemen & SystemBC: A Sneak Peek Behind the Proxy

ID: 78a84eeb-34aa-55cf-8fb7-d8c4ae09a6f5

STIX ID: report--78a84eeb-34aa-55cf-8fb7-d8c4ae09a6f5

Feed Name: Check Point Research

Threat Score
90/100

Date Published: 2026-04-20

Date Updated: 2026-04-27

Author: [email protected]

...
...

**Executive summary:** The report analyzes "The Gentlemen" RaaS—an active, multi‑platform ransomware affiliate ecosystem (Windows/Linux/ESXi) that has publicly claimed ~320 victims and is associated with SystemBC and a botnet of >1,570 infected hosts; it includes a DFIR timeline, detailed TTPs (credential theft, PsExec/WMI/PsExec/Group Policy mass deployment, Defender/firewall disabling), full technical breakdown of encryption/persistence, and extensive IOCs and a YARA rule for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.