logo

TheGentlemen Ransomware Toolkit Found on Russian Proton66 Server

ID: 3410cedf-cfb8-5326-8fd0-5f1c1996fce4

STIX ID: report--3410cedf-cfb8-5326-8fd0-5f1c1996fce4

Feed Name: Hunt.io Blog

Threat Score
80/100

Date Published: 2026-03-25

Date Updated: 2026-04-28

...
...

On 2026-03-12 Hunt.io discovered an exposed Proton66 open directory hosting a structured TheGentlemen RaaS operator toolkit (126 files, ~140MB) containing Mimikatz logs with harvested NTLM hashes, comprehensive pre-encryption scripts (notably z1.bat) that disable protections, delete VSS snapshots, create SMB shares, install backdoors (ngrok/RustDesk) and clear logs, plus two exposed ngrok auth tokens and numerous dual-use utilities — providing strong evidence of active ransomware operations, actionable IOCs, and mapped MITRE ATT&CK TTPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.