PULSE NAME
The Gentlemen & SystemBC: A Sneak Peek Behind the Proxy
WHITE The Gentlemen AlienVault 2026-04-20 Modified: 2026-04-20
46
IOCs
MEDIUM VOLUME
The Gentlemen ransomware-as-a-service program has rapidly expanded since mid-2025, claiming over 320 victims with 240 attacks occurring in early 2026. The service provides multi-platform lockers for Windows, Linux, NAS, BSD, and ESXi, enabling comprehensive coverage of corporate environments. During an incident response engagement, an affiliate deployed SystemBC proxy malware for covert tunneling and payload delivery. Analysis of the SystemBC command-and-control server revealed a botnet of over 1,570 victims, primarily corporate and organizational targets. The intrusion progressed from domain controller compromise through credential validation, remote execution via administrative shares, and deployment of Cobalt Strike payloads. Attackers disabled defenses, established persistence through scheduled tasks and services, and ultimately deployed ransomware via Group Policy. The operation demonstrates sophisticated lateral movement capabilities, defense evasion techniques, and integration of mature post-exploit...
Indicators of Compromise (8 / 46 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 f4ae5b89db5a6a36dbd98287ab7c860a 2026-04-20
FileHash-MD5 30b49ae2f685d4403d3013410f80c2e2 2026-04-20
FileHash-MD5 4200b46a93c6ab059e2b34ce200c4a5b 2026-04-20
FileHash-MD5 44118d8fb41634b3d8d8b1c6fdf9c421 2026-04-20
FileHash-MD5 5f5bf7fc7a9ac89ce0bbb07bd1160078 2026-04-20
FileHash-MD5 6ae7c9a7ea0b8c40a64225734f6bd01d 2026-04-20
FileHash-MD5 c9d004384de06bbc53724b1431dc0fde 2026-04-20
FileHash-MD5 de1a114a2c5552387a1bbb61501bf129 2026-04-20