On May 4th, 2026, The Gentlemen RaaS administrator acknowledged that an internal backend database called Rocket had been leaked, exposing nine accounts including zeta88, the program's effective administrator. The leak revealed internal discussions detailing initial access methods through Fortinet and Cisco edge appliances, NTLM relay, and credential logs, along with the group's role divisions and toolsets. Evidence shows evaluation of CVEs including CVE-2024-55591, CVE-2025-32433, and CVE-2025-33073. Leaked ransom negotiations showed a successful payment of 190,000 USD. The group reused stolen data from a UK software consultancy to attack a Turkish company, employing dual-pressure tactics during negotiations. Analysis of ransomware samples identified eight distinct affiliate TOX IDs, indicating the administrator actively participates in infections alongside managing the RaaS program.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
The Gentlemen ransomware as a service (RaaS) group operates with high sophistication, targeting transportation and construction sectors in the UK. Leaked internal communications reveal use of Fortinet/Cisco edge appliance vulnerabilities, NTLM relay attacks, and credential theft. The group leverages stolen data for secondary attacks and employs dual-pressure tactics during negotiations. Their affiliate model and active participation in infections make them a significant threat to critical infrastructure globally.
Goals & Targeting
The Gentlemen RaaS group targets transportation and construction sectors due to their potential for high-value data and larger organizational footprints, making them attractive for both initial access and secondary extortion. Their primary motivation appears to be financial gain, as evidenced by successful ransom negotiations and affiliate structures designed to maximize profit. The targeting of the UK suggests a focus on developed economies with weaker security postures or industries where downtime translates into significant economic losses.
Enhanced Description
The Gentlemen RaaS administrator's internal database leak on May 4th, 2026, exposed critical operational details, including infection methods, toolsets, and affiliate IDs. The group specializes in exploiting CVEs such as 2024-55591, 2025-32433, and 2025-33073 to gain initial access through Fortinet and Cisco appliances using NTLM relay attacks. Their toolset includes Cobalt Strike for initial access, Mimikatz for credential dumping, and custom ransomware deployment. The leak revealed a successful $190,000 ransom payment and a notable shift in targeting after reusing stolen data from a UK software consultancy to attack a Turkish company. This dual-pressure tactic during negotiations underscores their strategic adaptability. The group's administration actively participates in infections while managing the RaaS program, indicating a hands-on-approach to operations.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The Gentlemen group's campaign patterns include targeting large transportation and construction firms in the UK, using a mix of stolen data and direct exploitation. Their operational tempo is steady, with affiliates actively seeking new infections while maintaining control over the RaaS program. Notable past operations include high-value ransomware deployments and successful extortion campaigns leveraging dual-pressure tactics. The group's active participation in infections suggests a hands-on-approach to ensure high success rates.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the technical details from the leaked database and observed TTPs. However, gaps exist in understanding the group's long-term strategic goals beyond financial gain and their full targeting criteria outside the UK.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
32
IOCs
0
Observed Data
0
Tactics