PRODAFT/KrebsOnSecurity Unmask The Gentlemen RaaS Operator LARVA-368 (Storm-2697) — 478 Victims, AI-Assisted Tooling, FortiGate Mass-Exploitation at Scale
PRODAFT published a comprehensive technical dossier on The Gentlemen RaaS, tracking the operator as LARVA-368 (aliases: hastalamuerte, zeta88, ArmCorp) and linking the group to 478 victims since March 2025 — roughly 10% of global ransomware activity in April 2026. The group's admin directly supplies affiliates with Fortinet SSL-VPN credentials sourced from brute-force attacks against a self-reported pre-compromised inventory of ~14,700 FortiGate devices, and uses AI to develop and maintain the Go-based encryptor and post-exploitation tooling. A 90/10 affiliate revenue split — well above the industry norm of 80/20 — is fueling aggressive recruitment of experienced operators from competing RaaS programs.
A 90/10 affiliate revenue split — well above the industry norm of 80/20 — is fueling aggressive recruitment of experienced operators from competing RaaS programs.
This intelligence brief has been compiled from open-source reporting and corroborated across multiple threat intelligence sources. Defenders should treat the high severity rating as a guide to prioritization within their environment.
For the latest indicators of compromise, formatted SIEM queries, and unredacted actor intelligence related to this brief, DMZ Operator subscribers receive automated IOC packages via email the moment new advisories are published.