logo

The Gentlemen Ransomware Group — Leak Analysis

ID: ae637caa-8dca-545f-bea5-41ba1866ea33

STIX ID: report--ae637caa-8dca-545f-bea5-41ba1866ea33

Feed Name: Ransomware ISAC Blog

Threat Score
85/100

Date Published: 2026-05-15

Date Updated: 2026-08-21

Author: [email protected] (Ransom-ISAC Research Team)

...
...

**Executive summary:** The report analyzes a partial public leak of The Gentlemen ransomware-as-a-service operation (22 Rocket.Chat rooms, ~3,366 messages) that reveals their organizational structure, FortiGate-focused access pipeline (CVE-2024-55591), bespoke tooling (G-BOT, FOBOS), Velociraptor repurposing, SOCKS5 pivoting, data exfiltration and negotiation workflows, 66 confirmed victims from the corpus (400+ publicly claimed overall), numerous IOCs (onion sites, hashes, BTC/Tox IDs), and recommended mitigations and detection guidance for SOCs and CERTs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.