logo

The “Gentlemen” Ransomware Toolkit and the Lethal z1.bat Pre-Encryption Weapon

ID: 36ff29c5-f0a8-5187-8dfe-76d29f5c77a5

STIX ID: report--36ff29c5-f0a8-5187-8dfe-76d29f5c77a5

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-03-30

Date Updated: 2026-04-23

Author: Ddos

...
...

Researchers found an organized, production-grade toolkit belonging to a TheGentlemen ransomware affiliate hosted in an open Proton66 directory; the toolkit includes Mimikatz logs, privilege-escalation utilities, ngrok tokens for reverse access, and a destructive pre-deployment script (z1.bat) that disables security products, purges registry entries, deletes volume shadow copies, and installs persistent backdoors, indicating active, high-impact ransomware operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.