PULSE NAME
The Gentlemen & SystemBC: A Sneak Peek Behind the Proxy
WHITE The Gentlemen AlienVault 2026-04-20 Modified: 2026-04-20
46
IOCs
MEDIUM VOLUME
The Gentlemen ransomware-as-a-service program has rapidly expanded since mid-2025, claiming over 320 victims with 240 attacks occurring in early 2026. The service provides multi-platform lockers for Windows, Linux, NAS, BSD, and ESXi, enabling comprehensive coverage of corporate environments. During an incident response engagement, an affiliate deployed SystemBC proxy malware for covert tunneling and payload delivery. Analysis of the SystemBC command-and-control server revealed a botnet of over 1,570 victims, primarily corporate and organizational targets. The intrusion progressed from domain controller compromise through credential validation, remote execution via administrative shares, and deployment of Cobalt Strike payloads. Attackers disabled defenses, established persistence through scheduled tasks and services, and ultimately deployed ransomware via Group Policy. The operation demonstrates sophisticated lateral movement capabilities, defense evasion techniques, and integration of mature post-exploit...
Indicators of Compromise (10 / 46 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 36d968425629b10f38be17787f8afe4b8afa131e 2026-04-20
FileHash-SHA1 2c27a865b3ab1f0bd2ea1e8f7298b5ef9348c5ac 2026-04-20
FileHash-SHA1 3e2272b916da4be3c120d17490423230ab62c174 2026-04-20
FileHash-SHA1 42bcc743c71a9ea083c1c750a398110582796762 2026-04-20
FileHash-SHA1 5264a94271d875675336a503c94ece0baceb58c5 2026-04-20
FileHash-SHA1 68225c5613afe2174ed46e074147676b0f9a3915 2026-04-20
FileHash-SHA1 8468cb5888fb383d25f9144c2b2f61c414cea3f8 2026-04-20
FileHash-SHA1 8cdfedf9416ef9e50548f02e5dfa5dd5aa38c586 2026-04-20
FileHash-SHA1 d6aaed67606d6dab0f652c755d3d363025f60adb 2026-04-20
FileHash-SHA1 f1025bb2f147c01742f263bc0b8d462af9728a22 2026-04-20