The Gentlemen Ransomware Group — Leak Analysis
ID: ae637caa-8dca-545f-bea5-41ba1866ea33
STIX ID: report--ae637caa-8dca-545f-bea5-41ba1866ea33
Feed Name: Ransomware ISAC Blog
Date Published: 2026-05-15
Date Updated: 2026-08-21
Author: [email protected] (Ransom-ISAC Research Team)
**Executive summary:** The report analyzes a partial public leak of The Gentlemen ransomware-as-a-service operation (22 Rocket.Chat rooms, ~3,366 messages) that reveals their organizational structure, FortiGate-focused access pipeline (CVE-2024-55591), bespoke tooling (G-BOT, FOBOS), Velociraptor repurposing, SOCKS5 pivoting, data exfiltration and negotiation workflows, 66 confirmed victims from the corpus (400+ publicly claimed overall), numerous IOCs (onion sites, hashes, BTC/Tox IDs), and recommended mitigations and detection guidance for SOCs and CERTs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
