logo

The Gentlemen Leak Analysis (Part 2) — JA456 Follow-on

ID: c7627e92-5daf-58e2-9cd7-83f9abe85ffb

STIX ID: report--c7627e92-5daf-58e2-9cd7-83f9abe85ffb

Feed Name: Ransomware ISAC Blog

Threat Score
85/100

Date Published: 2026-05-26

Date Updated: 2026-08-21

Author: [email protected] (Ransom-ISAC Research Team)

...
...

JA456 is a follow-on leak exposing operator-side artifacts and victim exfiltration tied to Zeta/The Gentlemen ransomware group: MEGA GDPR export and session logs, a Synology NAS shadow dump and wipe-in-progress screenshots, plus stolen victim materials including a pharma regulatory dossier and a domain controller VSS backup containing NTDS. The package includes high-value IOCs (multiple IPs including a residential Izhevsk IP 92.39.211.142, NAS serial 34POALFLF3XJ, MEGA tokens, rclone/MEGAsync fingerprints) and a timeline that supports infrastructure mapping, attribution, and immediate defensive actions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.