Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors the gentlemen

Description

On May 4th, 2026, The Gentlemen RaaS administrator acknowledged that an internal backend database called Rocket had been leaked, exposing nine accounts including zeta88, the program's effective administrator. The leak revealed internal discussions detailing initial access methods through Fortinet and Cisco edge appliances, NTLM relay, and credential logs, along with the group's role divisions and toolsets. Evidence shows evaluation of CVEs including CVE-2024-55591, CVE-2025-32433, and CVE-2025-33073. Leaked ransom negotiations showed a successful payment of 190,000 USD. The group reused stolen data from a UK software consultancy to attack a Turkish company, employing dual-pressure tactics during negotiations. Analysis of ransomware samples identified eight distinct affiliate TOX IDs, indicating the administrator actively participates in infections alongside managing the RaaS program.

Goals & Targeting

Targeted Sectors

Transportation
Construction

Targeted Countries / Regions

United Kingdom of Great Britain and Northern Ireland

AI Analysis

· 1 week ago

Executive Summary

The Gentlemen ransomware as a service (RaaS) group operates with high sophistication, targeting transportation and construction sectors in the UK. Leaked internal communications reveal use of Fortinet/Cisco edge appliance vulnerabilities, NTLM relay attacks, and credential theft. The group leverages stolen data for secondary attacks and employs dual-pressure tactics during negotiations. Their affiliate model and active participation in infections make them a significant threat to critical infrastructure globally.

Goals & Targeting

The Gentlemen RaaS group targets transportation and construction sectors due to their potential for high-value data and larger organizational footprints, making them attractive for both initial access and secondary extortion. Their primary motivation appears to be financial gain, as evidenced by successful ransom negotiations and affiliate structures designed to maximize profit. The targeting of the UK suggests a focus on developed economies with weaker security postures or industries where downtime translates into significant economic losses.

Enhanced Description

The Gentlemen RaaS administrator's internal database leak on May 4th, 2026, exposed critical operational details, including infection methods, toolsets, and affiliate IDs. The group specializes in exploiting CVEs such as 2024-55591, 2025-32433, and 2025-33073 to gain initial access through Fortinet and Cisco appliances using NTLM relay attacks. Their toolset includes Cobalt Strike for initial access, Mimikatz for credential dumping, and custom ransomware deployment. The leak revealed a successful $190,000 ransom payment and a notable shift in targeting after reusing stolen data from a UK software consultancy to attack a Turkish company. This dual-pressure tactic during negotiations underscores their strategic adaptability. The group's administration actively participates in infections while managing the RaaS program, indicating a hands-on-approach to operations.

Key Capabilities

  • Exploitation of Fortinet/Cisco edge appliance vulnerabilities
  • NTLM relay attacks for initial access
  • Credential theft and reuse
  • Dual-pressure negotiation tactics
  • Affiliate-driven infection model
  • Custom ransomware deployment

MITRE ATT&CK Tactics

Initial Access
Execution
Lateral Movement
Credential Access
Extraction

ATT&CK Techniques

T1059 - Command-Line Interface
T1383 - Data Leak via Paste
T1497 - Exploitation Framework
T1078 - Discovery
T1093 - Ingress Tool Transfer

Software / Tooling

Cobalt Strike
Mimikatz
Custom Ransomware
The Gentlemen RaaS

Campaigns & Victims

The Gentlemen group's campaign patterns include targeting large transportation and construction firms in the UK, using a mix of stolen data and direct exploitation. Their operational tempo is steady, with affiliates actively seeking new infections while maintaining control over the RaaS program. Notable past operations include high-value ransomware deployments and successful extortion campaigns leveraging dual-pressure tactics. The group's active participation in infections suggests a hands-on-approach to ensure high success rates.

IOC Patterns

  • Exploitation of Fortinet/Cisco edge appliances
  • NTLM relay attacks for initial access
  • Use of Cobalt Strike for phishing and payload delivery
  • Ransomware negotiation via encrypted channels
  • Reused stolen credentials from prior breaches

Recommended Actions

  • Monitor Fortinet/Cisco appliances for signs of exploitation attempts
  • Implement multi-factor authentication (MFA) on critical systems
  • Patch all CVEs linked to The Gentlemen's exploit list
  • Enhance incident response plans to detect and mitigate NTLM relay attacks
  • Monitor employee communications for signs of affiliate activity

Suggested Tags

Ransomware
Exploitation
Affiliate Program
Transportation Sector
Construction Sector

Confidence Assessment

High confidence in the technical details from the leaked database and observed TTPs. However, gaps exist in understanding the group's long-term strategic goals beyond financial gain and their full targeting criteria outside the UK.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 3 Domain 9 URL 8

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

32

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Critical Infrastructure
Data Exfiltration
Exploitation
Affiliate Program
Transportation Sector
Construction Sector

Details

Type
Unknown
Confidence
60%
Added
May 14, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.