Based on the detailed analysis provided in the report, here are the key points regarding The Gentlemen ransomware group:
-
RaaS Model:
- The Gentlemen operates as a Ransomware-as-a-Service (RaaS) platform.
- It has a panel and builder for distributing malware to affiliates.
-
Infrastructure:
- Uses Linux-based infrastructure with containers and a TOR front-end.
- Has a custom ransomware locker that can spread via Group Policy Objects (GPO).
-
Operational Structure:
- Centralized control by the main operator, likely "hastalamuerte" who also uses the handle "zeta88".
- Affiliates and operators like "qbit" and "quant" carry out day-to-day operations.
-
Communication Channels:
- Uses internal chat channels for coordination.
- Channels include INFO, general, TOOLS, and PODBOR (for target selection).
-
Targeting Strategy:
- Focuses on corporate victims.
- Discusses selecting targets ("подбор" or "selection").
- Assigns groups of 2-3 people to specific campaigns.
-
**Technical
Read the full article at Check Point Research
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.





