Tuesday , September 29 2026
Gentlemen Ransomware

The Gentlemen Ransomware Attacks Windows, Linux, NAS, BSD, and ESXi Systems

The Gentlemen ransomware group has quickly become one of the most active and growing cybercrime threats since it was first seen in late 2025. The Gentlemen is unique because it has the capability to attack with many types of systems, such as Windows, Linux, NAS, BSD, and VMware ESXi.

Attack chains seen in incidents include using open remote services, stealing credentials, and misusing VPN or firewall access.

Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

Apple has launched iOS 26.7.1 and iPadOS 26.7.1 to fix a serious zero-day flaw that it believes might have been...
Read More
Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

JadePuffer Agentic AI targets and destroys Azure’s cloud resources

The JadePuffer ransomware group is attacking Azure users with agent-based attacks that gather information, steal passwords, and damage key components. The...
Read More
JadePuffer Agentic AI targets and destroys Azure’s cloud resources

“InfoSecCon-2026: Bangladesh’s Cybersecurity Leaders Unite to Shape a Safer Digital Future”

The 5th Edition of InfoSecCon-2026, a premier cybersecurity-focused event, has been successfully completed with the participation of cybersecurity professionals, technology...
Read More
“InfoSecCon-2026: Bangladesh’s Cybersecurity Leaders Unite to Shape a Safer Digital Future”

Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The...
Read More
Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Amazon Web Services cannot restore access to its cloud-computing facility in Bahrain and ‌one of three data-hosting zones in the...
Read More
AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that...
Read More
Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

Anthropic prepares “Claude Money” to analyze bank account and financial data

Anthropic is making a new Claude feature called “Money.” It's a separate tab in the mobile app. The new interface...
Read More
Anthropic prepares “Claude Money” to analyze bank account and financial data

GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

GhostCode is a new phishing kit that changes a regular Microsoft 365 sign-in into an account theft. It doesn't need...
Read More
GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

VPN flaw exposed 246,000 personnel records in japan

Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
VPN flaw exposed 246,000 personnel records in japan

Security researchers at Levelblue believe the group is not completely new. It seems to be a continuation of past ransomware activity, linked to the Qilin group and a Russian-speaking person called “hastalamuerte.”

                                       The Gentlemen’s related Illustration spotted on the dark web (Source : LevelBlue).

Attackers go into the system, look around the network, gain higher access, disable security tools, and spread ransomware. They also steal data, which is an important part of their double extortion plan.

Ransomware-as-a-Service Model

The Gentlemen runs a planned ransomware-as-a-service (RaaS) system with a special partner panel. This system is said to help create malware, customize ransom notes, track victims, and manage negotiations.

The Gentlemen’s account on X (Source : LevelBlue).

Affiliates may also use external communication tools like Tox or Session, complicating incident tracking.

The group’s ransom note is called “README-GENTLEMEN.txt.” It comes with encrypted files that have endings like “.7mtzhh” or other random types.

The malware is said to be made in Go and needs a password to run. This helps users manage its use and avoid automatic checks. Encryption uses a mixed approach. Small files are completely encrypted, while big files are partly encrypted in pieces to speed up the process.

Before encryption, the malware stops services related to backups, databases, and business apps to make recovery harder. Activity covers more than 70 countries. The biggest portions are in APAC (28.7%), Europe (28.4%), and the Americas.

The United States is at the top, then comes Thailand, France, and Brazil. Russia and CIS countries are missing, which fits usual ransomware patterns.

Recently, hidden online groups have made claims about data that they say is connected to the group, sold for about $10,000 in Bitcoin.

Organizations should focus on securing remote access services, using multi-factor authentication, watching privileged accounts, and making sure to have strong, separate backups.

Early detection strategies should look for strange actions by attackers. This includes unusual admin work, moving sideways in the network, and getting data ready before ransomware strikes.

Check Also

Secure Email Gateway

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known …