Gentlemen Ransomware Targets Windows, Linux, NAS, BSD, and ESXi Systems
ID: df1e2d67-0ea3-5c49-9b0f-d1ef944544b7
STIX ID: report--df1e2d67-0ea3-5c49-9b0f-d1ef944544b7
Feed Name: GBHackers
**Executive summary:** The report profiles 'The Gentlemen' ransomware-as-a-service: an affiliate-driven, cross-platform ransomware operation (Windows, Linux, NAS, BSD, VMware ESXi) that performs credential abuse and exploitation of exposed services, conducts network reconnaissance and privilege escalation, disables backups/security, exfiltrates data for double extortion, and deploys a Go-based hybrid-encryption payload (README-GENTLEMEN.txt / extensions like .7mtzhh); the group claimed 352 victims publicly with IR data suggesting ~1,500 affected environments across multiple industries and geographies, and the report recommends securing remote access, enforcing MFA, monitoring privileged activity, and maintaining isolated backups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
