The Gentlemen Leak Analysis (Part 2) — JA456 Follow-on
ID: 79a54b75-1feb-5b89-a992-6dce6f4f95ad
STIX ID: report--79a54b75-1feb-5b89-a992-6dce6f4f95ad
Feed Name: Ransomware ISAC Blog
Date Published: 2026-05-26
Date Updated: 2026-07-29
Author: [email protected] (Ransom-ISAC Research Team)
JA456 — a follow-on to the “Gentlemen Leaks” corpus — exposes operator-side artifacts and victim data from the Zeta (The Gentlemen) ransomware group: MEGA GDPR export and session history, Synology NAS /etc/shadow and screenshots showing a factory reset while exfiltration was active, plus stolen victim materials including a pharma regulatory dossier and a Windows Server DC VSS backup containing NTDS. The report provides IOCs (notably 92.39.211.142, 178.130.46.120, 193.228.128.2), a timeline, TTPs (rclone→NAS→MEGA), and an assessment linking activity to Izhevsk, Russia for defensive prioritization.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
