Ransomware Affiliate Exposes Details of 'The Gentlemen' Operation
ID: 6ff73103-491e-5795-8253-1a55f2fa7abc
STIX ID: report--6ff73103-491e-5795-8253-1a55f2fa7abc
Feed Name: Infosecurity Magazine (News)
Group-IB research disclosed that the emerging RaaS group "The Gentlemen" operates a dual-extortion ransomware model across Windows, Linux and ESXi environments, leverages exposed FortiGate VPN devices or brute force for initial access, and uses automated lateral movement, backup disruption, BYOVD, and aggressive log deletion to maximize impact and evade detection; an affiliate leak revealed internal disputes and provided rare visibility into their infrastructure and tactics.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
