logo

Gentlemen Ransomware Exploits Fortinet Flaws, AI, and Custom C2 Tools

ID: d1d04a4f-ce7b-5436-a58b-a567a5c87667

STIX ID: report--d1d04a4f-ce7b-5436-a58b-a567a5c87667

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-06-03

Date Updated: 2026-06-03

Author: Mayura Kathir

...
...

Leaked Rocket.Chat logs attributed to The Gentlemen ransomware group reveal continued operator reuse across major ransomware brands and show active exploitation of Fortinet edge devices (including CVE-2024-55591), widespread brute-force of ~1,000 VPNs using weak credentials, use of AI for social engineering, proprietary C2 tooling (G-BOT), advanced EDR-evasion techniques, hypervisor-level VM encryption, credential harvesting and data exfiltration to cloud storage — collectively demonstrating high-risk, ongoing ransomware operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.