Wednesday , September 9 2026
Gentlemen Ransomware

The Gentlemen Ransomware Attacks Windows, Linux, NAS, BSD, and ESXi Systems

The Gentlemen ransomware group has quickly become one of the most active and growing cybercrime threats since it was first seen in late 2025. The Gentlemen is unique because it has the capability to attack with many types of systems, such as Windows, Linux, NAS, BSD, and VMware ESXi.

Attack chains seen in incidents include using open remote services, stealing credentials, and misusing VPN or firewall access.

A single call: ShinyHunters Gained Access to 6 Million Customers’ Records

A single phone call caused one of the biggest data breaches in Dutch history. In early February 2026, the big...
Read More
A single call: ShinyHunters Gained Access to 6 Million Customers’ Records

The first zero-click worm to spread through WeChat calls across iOS and Android

A worm called “WeWorm” can spread through WeChat voice calls on iOS and Android. It takes over a target's WeChat...
Read More
The first zero-click worm to spread through WeChat calls across iOS and Android

USA Bimbo Bakeries Confirms Data Stolen in Oracle EBS Zero-Day Attack

Bimbo Bakeries USA has confirmed that hackers stole employee data by exploiting a zero-day vulnerability in Oracle’s E-Business Suite (EBS). In...
Read More
USA Bimbo Bakeries Confirms Data Stolen in Oracle EBS Zero-Day Attack

ALERT
Roundcube Webmail fixes 12 security flaws, including zero-click XSS and SSRF bypass

Roundcube Webmail has given security updates for its 1.6 LTS and 1.7 branches. These updates fix 12 problems that could...
Read More
ALERT  Roundcube Webmail fixes 12 security flaws, including zero-click XSS and SSRF bypass

New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Russian-backed hacker group BlueDelta, also known as APT28, Fancy Bear, and Forest Blizzard, has used a small Windows backdoor called...
Read More
New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

Attackers are misusing MikroTik routers through their Secure Shell (SSH) service, which can be accessed from the internet, to take...
Read More
Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

CrowdStrike launches SafeMind, the first agentic cybersecurity solution for defenders

CrowdStrike launched CrowdStrike SafeMind, a set of special security models and tools from the CrowdStrike Cyber Superintelligence Lab. The SafeMind...
Read More
CrowdStrike launches SafeMind, the first agentic cybersecurity solution for defenders

Claude, DeepSeek, and Qwen AI agents combinedly used to hit gov.t across Asia

Chinese-speaking hackers have added Claude, Qwen, and DeepSeek to their hacking system to automate cyberattacks on governments and other targets...
Read More
Claude, DeepSeek, and Qwen AI agents combinedly used to hit gov.t across Asia

India: C-DOT Launches 14 Local Quantum-Safe Technologies

India is making its communication systems safer and stronger by launching 14 local quantum products. These products were made by...
Read More
India: C-DOT Launches 14 Local Quantum-Safe Technologies

14,000 Dahua cameras compromised: TP-Link flaws enable RCE

Over 14,000 Dahua security cameras connected to the internet have been hacked in a 35-day online attack that affected devices...
Read More
14,000 Dahua cameras compromised: TP-Link flaws enable RCE

Security researchers at Levelblue believe the group is not completely new. It seems to be a continuation of past ransomware activity, linked to the Qilin group and a Russian-speaking person called “hastalamuerte.”

                                       The Gentlemen’s related Illustration spotted on the dark web (Source : LevelBlue).

Attackers go into the system, look around the network, gain higher access, disable security tools, and spread ransomware. They also steal data, which is an important part of their double extortion plan.

Ransomware-as-a-Service Model

The Gentlemen runs a planned ransomware-as-a-service (RaaS) system with a special partner panel. This system is said to help create malware, customize ransom notes, track victims, and manage negotiations.

The Gentlemen’s account on X (Source : LevelBlue).

Affiliates may also use external communication tools like Tox or Session, complicating incident tracking.

The group’s ransom note is called “README-GENTLEMEN.txt.” It comes with encrypted files that have endings like “.7mtzhh” or other random types.

The malware is said to be made in Go and needs a password to run. This helps users manage its use and avoid automatic checks. Encryption uses a mixed approach. Small files are completely encrypted, while big files are partly encrypted in pieces to speed up the process.

Before encryption, the malware stops services related to backups, databases, and business apps to make recovery harder. Activity covers more than 70 countries. The biggest portions are in APAC (28.7%), Europe (28.4%), and the Americas.

The United States is at the top, then comes Thailand, France, and Brazil. Russia and CIS countries are missing, which fits usual ransomware patterns.

Recently, hidden online groups have made claims about data that they say is connected to the group, sold for about $10,000 in Bitcoin.

Organizations should focus on securing remote access services, using multi-factor authentication, watching privileged accounts, and making sure to have strong, separate backups.

Early detection strategies should look for strange actions by attackers. This includes unusual admin work, moving sideways in the network, and getting data ready before ransomware strikes.

Check Also

Dahua

14,000 Dahua cameras compromised: TP-Link flaws enable RCE

Over 14,000 Dahua security cameras connected to the internet have been hacked in a 35-day …