The Gentlemen Ransomware Group — Leak Analysis
ID: 62192e6a-2f49-5845-9466-9ab46e97805f
STIX ID: report--62192e6a-2f49-5845-9466-9ab46e97805f
Feed Name: Ransomware ISAC Blog
Date Published: 2026-05-15
Date Updated: 2026-07-29
Author: [email protected] (Ransom-ISAC Research Team)
**Executive Summary:** The leaked Rocket.Chat corpus from The Gentlemen RaaS reveals a professionally organised ransomware operation (emerged Jul–Aug 2025) that exploited Fortinet vulnerabilities (CVE-2024-55591 and others), reused branded VPN credentials, operated custom C2 (G-BOT), repurposed Velociraptor, performed large-scale credential theft/exfiltration (rclone, XenAllPasswordPro), integrated AI for negotiation/triage, and impacted hundreds of victims (66 confirmed in this 6-month window, ~400+ publicly attributed), providing rich TTPs, IOCs (hashes, BTC addresses, .onion endpoints, Tox IDs), and concrete detection/hardening guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
