Tuesday , July 28 2026
Gentlemen Ransomware

The Gentlemen Ransomware Attacks Windows, Linux, NAS, BSD, and ESXi Systems

The Gentlemen ransomware group has quickly become one of the most active and growing cybercrime threats since it was first seen in late 2025. The Gentlemen is unique because it has the capability to attack with many types of systems, such as Windows, Linux, NAS, BSD, and VMware ESXi.

Attack chains seen in incidents include using open remote services, stealing credentials, and misusing VPN or firewall access.

Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

CISA has put the Fortinet FortiOS vulnerability CVE-2025-68686 in its list of known exploited flaws after ongoing attacks. The flaw...
Read More
Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

OpenAI's CEO Sam Altman says that AI has reached a big milestone. The technology can now make itself better, leading...
Read More
Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

Shinyhunters claimed and set deadline to publish E&Y data

ShinyHunters has publicly claimed responsibility for the Ernst & Young (EY) data breach. The group posted a message on their...
Read More
Shinyhunters claimed and set deadline to publish E&Y data

Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Nvidia and over 30 tech firms started a group on Monday to create open-source AI tools for protecting against cyber...
Read More
Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Google Search Results Reportedly Show Claude AI Shared Chats

Claude's share links from Anthropic showed up in public search results. This raised new privacy worries for users who shared...
Read More
Google Search Results Reportedly Show Claude AI Shared Chats

“PentesterFlow” AI Automation Tool for Penetration Testers and Bug Hunters

PentesterFlow is a new open-source AI tool for command lines. It is made for penetration testers and bug bounty hunters....
Read More
“PentesterFlow” AI Automation Tool for Penetration Testers and Bug Hunters

Jailbreak works against AI Models GPT-5.6, Claude Opus 5, and Fable, Claims Researcher

A famous AI red team expert claimed developing a universal jailbreak that can work against top large language models, like...
Read More
Jailbreak works against AI Models GPT-5.6, Claude Opus 5, and Fable, Claims Researcher

Researchers found security flaws in every script generated by ChatGPT, Copilot, and Gemini

A new study from Beacom College shows that all automation scripts produced by top AI models like ChatGPT, Microsoft Copilot,...
Read More
Researchers found security flaws in every script generated by ChatGPT, Copilot, and Gemini

Australian Energy Giant Origin confirms unauthorized access and disclosure of customer data

Origin Energy Limited, a major energy provider in Australia, has said there was a cybersecurity issue with unauthorized access to...
Read More
Australian Energy Giant Origin confirms unauthorized access and disclosure of customer data

Anthropic Unveils Claude Security Plugin for Code Flaw Scanning

Anthropic launched the Claude Security plugin in beta. This tool uses AI to find serious security flaws in Claude Code....
Read More
Anthropic Unveils Claude Security Plugin for Code Flaw Scanning

Security researchers at Levelblue believe the group is not completely new. It seems to be a continuation of past ransomware activity, linked to the Qilin group and a Russian-speaking person called “hastalamuerte.”

                                       The Gentlemen’s related Illustration spotted on the dark web (Source : LevelBlue).

Attackers go into the system, look around the network, gain higher access, disable security tools, and spread ransomware. They also steal data, which is an important part of their double extortion plan.

Ransomware-as-a-Service Model

The Gentlemen runs a planned ransomware-as-a-service (RaaS) system with a special partner panel. This system is said to help create malware, customize ransom notes, track victims, and manage negotiations.

The Gentlemen’s account on X (Source : LevelBlue).

Affiliates may also use external communication tools like Tox or Session, complicating incident tracking.

The group’s ransom note is called “README-GENTLEMEN.txt.” It comes with encrypted files that have endings like “.7mtzhh” or other random types.

The malware is said to be made in Go and needs a password to run. This helps users manage its use and avoid automatic checks. Encryption uses a mixed approach. Small files are completely encrypted, while big files are partly encrypted in pieces to speed up the process.

Before encryption, the malware stops services related to backups, databases, and business apps to make recovery harder. Activity covers more than 70 countries. The biggest portions are in APAC (28.7%), Europe (28.4%), and the Americas.

The United States is at the top, then comes Thailand, France, and Brazil. Russia and CIS countries are missing, which fits usual ransomware patterns.

Recently, hidden online groups have made claims about data that they say is connected to the group, sold for about $10,000 in Bitcoin.

Organizations should focus on securing remote access services, using multi-factor authentication, watching privileged accounts, and making sure to have strong, separate backups.

Early detection strategies should look for strange actions by attackers. This includes unusual admin work, moving sideways in the network, and getting data ready before ransomware strikes.

Check Also

Oracle

Oracle fixes 1,400+ vulnerabilities; critical flaws threaten enterprise servers

Oracle has fixed over 1,400 security holes in its July 2026 Critical Patch Update (CPU). …