DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:03:37ZSOURCES: 14CRITICAL: 15
⚠ ACTIVE ALERTS
SYLVANITE CRITICAL — SYLVANITE is a newly named Dragos-tracked threat group identified as a dedicated… /// @MsftSecIntel CRITICAL — We are tracking TeamPCP (UNC6780) activity following the GitHub internal repository… /// @GossiTheDog CRITICAL — The GitHub / TeamPCP breach is now being monetized on BreachForums. Listing is up — $95k… /// @struppigel CRITICAL — SUPPLY CHAIN ALERT: Laravel-Lang PHP packages backdoored May 22-23 via hijacked GitHub… /// @MalwareHunterTeam CRITICAL — Seeing fresh DebugElevator stealer log batches already appearing for sale on Exploit.in —…
15Critical Threats
8Active CVEs
0IOCs Tracked
0New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // THE-GENTLEMEN-RAASFIRST SEEN: JUL 2025

The Gentlemen

ALSO KNOWN AS: ArmCorp (former identity), hastalamuerte / zeta88 (operator handle)
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Russia (Russian-speaking operation)
ATTRIBUTION:ORGANIZED CRIME
STATUS:ACTIVE
FIRST OBSERVED:JUL 2025
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL69/100
RESOURCES69/100
PERSISTENCE72/100
STEALTH64/100
IMPACT78/100

The Gentlemen is the breakout ransomware group of Q1 2026, climbing to #2 globally with 400+ public victims in under 10 months of operation. Founded by 'hastalamuerte,' a former senior Qilin affiliate who departed after a $48,000 commission dispute, the group arrived with a pre-staged stockpile of approximately 14,700 compromised FortiGate devices (exploited via CVE-2024-55591) and 969 validated brute-forced VPN credentials. On May 4, 2026, the group itself was breached by an anonymous party who exfiltrated its internal database from hosting provider 4VPS, exposing full operational structure, ransom negotiations, and confirmed use of DeepSeek and Qwen AI models to accelerate ransomware development. Chain-victimization — using data from one victim to attack that victim's clients — is a confirmed tactic.

Financial extortion via double-extortion RaaS with globally diversified targeting; deliberate avoidance of US targets to reduce law enforcement exposure

CVE-2024-55591 (FortiOS/FortiProxy authentication bypass), CVE-2025-32433, NTLM relay (CVE-2025-33073), Active Directory enumeration, BYOVD EDR disablement, antivirus killers, SystemBC proxy malware for covert tunneling, Group Policy-driven domain-wide ransomware deployment, browser session harvesting (M365/Okta), credential broker purchasing, infostealer log markets for initial access, AI coding assistants (DeepSeek/Qwen) for malware development, double extortion (encryption + DLS publication), chain-victimization (supply chain lateral targeting), reverse-engineered encryption routines from Babuk/Qilin/LockBit 5.0/Medusa

MANUFACTURING
HEALTHCARE
PROFESSIONAL SERVICES
MATERIALS
CONSUMER GOODS
INFORMATION TECHNOLOGY
FINANCIAL SERVICES

Tor-based data leak site; RocketChat-based affiliate communications; 4VPS hosting (now compromised); ~14,700 pre-staged FortiGate ORB nodes globally concentrated in APAC and Latin America; qTox and Session apps for victim negotiation; in-development in-house LLM tooling

FILE DATE: JUL 2025
Launch & FortiGate Stockpile Activation
Group launched with pre-staged access from ~14,700 FortiGate devices compromised via CVE-2024-55591; published 38 victims in first weeks of operation, making it the fastest ransomware group to 150 victims in ecosystem history (9 months vs DragonForce's 2 years).
FILE DATE: FEB 2026
Q1 2026 Surge — 166 Victims
Posted 166 victims in Q1 2026 (315% QoQ increase), becoming the █████████████████ by victim count; February alone saw 82 victims in a single month; geographic concentration in Thailand (10.8%) and Brazil as artifacts of FortiGate stockpile distribution.
FILE DATE: MAY 2026
Internal Database Breach & Leak
Anonymous actor breached The Gentlemen's backend infrastructure via 4VPS hosting provider on May 4, 2026, exfiltrating chat logs, org rosters, negotiation transcripts, and tooling discussions — providing unprecedented defender visibility into a live ransomware operation.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn