Monday , August 10 2026
Gentlemen

Bangladeshi org listed “the Gentlemen’ ransomware victim list: CIRT warns

The gentlemen ransomware group targets various industries of Bangladesh. In an advisory Bangladesh e-Government Computer Incident Response Team (BGD e-GOV CIRT) warned that the ransomware operates under a Ransomware-as-a-Service (RaaS) model and is capable of rapidly spreading across corporate networks, encrypting Windows and Linux systems, network storage devices and VMware ESXi environments.

The biggest worry for Bangladesh is that the malware can take over a Domain Controller and possibly spread ransomware all over a company in just minutes.

Bangladeshi org listed “the Gentlemen’ ransomware victim list: CIRT warns

The gentlemen ransomware group targets various industries of Bangladesh. In an advisory Bangladesh e-Government Computer Incident Response Team (BGD e-GOV...
Read More
Bangladeshi org listed “the Gentlemen’ ransomware victim list: CIRT warns

Around 800 Malicious npm Packages Distribute Cross-Platform RAT and Infostealer

A group of almost 800 harmful packages was added to the npm registry in a new effort to spread malware...
Read More
Around 800 Malicious npm Packages Distribute Cross-Platform RAT and Infostealer

Google Chrome 151 Update Fixes 41 Flaws, 6 Critical

Google has launched Chrome version 151.0.7922.108/.109 for Windows and macOS, and version 151.0.7922.108 for Linux. This update brings 41 security...
Read More
Google Chrome 151 Update Fixes 41 Flaws, 6 Critical

Swiss gov.t SharePoint incident compromised 200 accounts

Switzerland’s federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. The...
Read More
Swiss gov.t SharePoint incident compromised 200 accounts

Azad president, Secretary Post Heads to Contest: ISACA Dhaka Chapter Election

The ISACA Dhaka Chapter Election for 2026–2028 will take place on 8, August-2026. Most of the executive roles are likely...
Read More
Azad president, Secretary Post Heads to Contest: ISACA Dhaka Chapter Election

Urgent patch! Cisco and IMB patch multiple flaws

Cisco has put out an important update for Cisco IOS XE Software. This update fixes serious security holes that could...
Read More
Urgent patch! Cisco and IMB patch multiple flaws

OWASP Unveils GenAI LLM Top 10 2026 For Modern AI APPS

The Open Web Application Security Project (OWASP) has published the Top 10 for LLM Applications 2026. This guide focuses on...
Read More
OWASP Unveils GenAI LLM Top 10 2026 For Modern AI APPS

Greatness PhaaS Evades Email Security and MFA to Take Over Microsoft 365 Accounts

Greatness has emerged as a phishing-as-a-service platform designed to steal Microsoft 365 access at a time when many organizations assume...
Read More
Greatness PhaaS Evades Email Security and MFA to Take Over Microsoft 365 Accounts

Pillar 4: Total 131 Indicators Set
How Bangladeshi’s Ogrs Be Evaluated By Newly Launched NRS & CIRS

Bangladesh's National Cyber Security Agency (NCSA) has launched two cybersecurity initiatives: the Cyber Incident Reporting System (CIRS) and the National...
Read More
Pillar 4: Total 131 Indicators Set  How Bangladeshi’s Ogrs Be Evaluated By Newly Launched NRS & CIRS

Brazilian health surveillance platform breach exposes 100K+ sensitive documents

Cybersecurity Researcher Jeremiah Fowler uncovered and reported to Express VPN a publicly exposed database that was neither password-protected nor encrypted....
Read More
Brazilian health surveillance platform breach exposes 100K+ sensitive documents
Source: BGD e-GOV CIRT

Bangladesh on the Threat Radar

According to CIRT, an NGO in Bangladesh was named on The Gentlemen’s extortion site in July 2026. The attackers said they would release stolen information on their site.

The event shows that more Bangladeshi companies are at risk from ransomware groups that steal data and demand money. CIRT found that areas like banking, finance, telecom, manufacturing, clothing, healthcare, education, NGOs, and government groups could be good targets.

A Single Compromised System Could Trigger a Network-Wide Attack

The Gentlemen ransomware is very dangerous because it can move easily through compromised networks. Once attackers get into one computer, they can use different tools like SMB, PsExec, WMI, PowerShell, Remote Scheduled Tasks, and Windows Services to infect more devices.

The danger becomes significantly greater if attackers obtain control of an organization’s Active Directory or Domain Controller.

CIRT said that hackers can use Group Policy and admin rights to spread ransomware to many systems, which could lead to the encryption of the entire company in just minutes.

Double Extortion Makes More Dangerous

The Gentlemen do not just encrypt files. They use a common double-extortion method: first, they steal important data, then they encrypt systems. If the ransom is not paid, victims are threatened with sharing the stolen data.

This creates two simultaneous risks for Bangladeshi organizations:

Operational disruption: critical systems and files become inaccessible.
Data exposure: confidential customer, employee, financial, business and beneficiary information may be leaked.

NGOs and development groups could face big problems if their databases are hacked. These databases may hold private information about helpers, donors, workers, and projects.

Vulnerable VPNs, Firewalls and Remote Systems Could Open the Door

CIRT pointed out that internet-connected systems are a great risk. Attackers can take advantage of weaknesses or get in through open VPN gateways, firewalls, backup systems, and hypervisor management tools.

Weak credentials, stolen passwords, outdated software and poorly configured Active Directory environments can further increase the risk.

CIRT asks organizations to closely watch technologies like Fortinet FortiOS/FortiProxy, Veeam Backup & Replication, and VMware ESXi, among others.

CIRT also cited threat intelligence indicating that the operators may have access to approximately 14,700 previously compromised FortiGate devices and 969 verified brute-forced VPN credential pairs.

CIRT Urges Immediate Defensive Measures

CIRT has urged organizations to take immediate steps to reduce their exposure. Key recommendations include:

Patch internet-facing firewalls, VPNs, backup systems and hypervisor infrastructure.
Enable phishing-resistant multi-factor authentication for remote and administrative accounts.
Strengthen security around Active Directory and Domain Controllers.
Disable SMBv1 and enable SMB signing.
Isolate VMware ESXi management interfaces from ordinary network traffic.
Enable endpoint detection and response and tamper protection.
Monitor for abnormal credential dumping and network-scanning activity.
Maintain offline, immutable or air-gapped backups.
Regularly test backup restoration procedures.
Segment critical systems to prevent rapid lateral movement.

The Warning for Bangladesh

The Gentlemen ransomware is a big threat to Bangladesh. It can quickly spread from one infected device and disrupt whole company networks. Its mix of RaaS, stealing data, double extortion, using stolen credentials, and attacking Domain Controllers makes it very dangerous. The presence of a Bangladeshi group on its extortion site shows the need for organizations to improve their internet-connected systems, secure accounts, Active Directory, network separation, and offline backups.

Related Topic:

How Bangladeshi’s Ogrs Be Evaluated By Newly Launched NRS & CIRS

Bangladesh Launches (CIRS) and National ICT & Cyber Security Rating System (NRS)

The Gentlemen Ransomware Attacks Windows, Linux, NAS, BSD, and ESXi Systems

Check Also

Pillar 4: Total 131 Indicators Set
How Bangladeshi’s Ogrs Be Evaluated By Newly Launched NRS & CIRS

Bangladesh’s National Cyber Security Agency (NCSA) has launched two cybersecurity initiatives: the Cyber Incident Reporting …