The Gentlemen ransomware now uses SystemBC for bot-powered attacks
ID: af010333-7974-521d-8cd4-b16b4ad8f04f
STIX ID: report--af010333-7974-521d-8cd4-b16b4ad8f04f
Feed Name: Bleeping Computer
Threat Score
**Executive Summary:** Check Point Research observed a Gentlemen ransomware affiliate deploying SystemBC proxy malware, revealing a botnet of more than 1,570 likely corporate hosts across the US, UK, Germany, Australia and Romania; the intrusion involved Domain Administrator access, credential harvesting (Mimikatz), Cobalt Strike, lateral movement and GPO-driven encryption using a hybrid X25519/XChaCha20 scheme, and Check Point published IoCs and a YARA rule to aid detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
