logo

The Gentlemen ransomware now uses SystemBC for bot-powered attacks

ID: af010333-7974-521d-8cd4-b16b4ad8f04f

STIX ID: report--af010333-7974-521d-8cd4-b16b4ad8f04f

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-04-20

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Executive Summary:** Check Point Research observed a Gentlemen ransomware affiliate deploying SystemBC proxy malware, revealing a botnet of more than 1,570 likely corporate hosts across the US, UK, Germany, Australia and Romania; the intrusion involved Domain Administrator access, credential harvesting (Mimikatz), Cobalt Strike, lateral movement and GPO-driven encryption using a hybrid X25519/XChaCha20 scheme, and Check Point published IoCs and a YARA rule to aid detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.