logo

Unmasked: 16GB “Rocket” Database Leak Exposes The Gentlemen Ransomware Cartel

ID: 7b695dd2-984c-5b37-8c97-3ecf51dc6bb8

STIX ID: report--7b695dd2-984c-5b37-8c97-3ecf51dc6bb8

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Ddos

...
...

### Executive summary A 16 GB leak of The Gentlemen RaaS backend ("Rocket") exposed operator chats, server logs, and transaction histories revealing a tightly coordinated ransomware cartel responsible for 330+ published victims in five months; the disclosure details initial access vectors (Fortinet/Cisco edge appliances), exploited CVEs (including CVE-2024-55591, CVE-2025-32433, CVE-2025-33073), NTLM relay/reflection tactics, custom evasion tools, AI-assisted development, and aggressive extortion workflows that materially raise the threat to internet-facing services and enterprise environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.