PULSE NAME
LBIOC-20260071 - The Gentlemens Leak
WHITE The Gentlemen AlienVault 2026-05-13 Modified: 2026-05-13
70
IOCs
HIGH VOLUME
The Gentlemen is an active ransomware and extortion operation that emerged publicly in the second half of 2025, rapidly escalating into a high-volume threat actor. The group appears to be a continuation or reorganization of prior ransomware affiliate activity, with reported connections to the Qilin ecosystem and the Russian-speaking actor 'hastalamuerte.' This growth likely reflects existing ransomware experience, affiliate relationships, and access to established resources. Underground sources indicate attempts to sell data allegedly connected to The Gentlemen ransomware activity, though the available information lacks sufficient victim-specific or technical details to confirm authenticity. The operation utilizes SystemBC for command and control communications and deploys ransomware variants targeting both Windows and Linux systems.
Indicators of Compromise (22 / 70 total)
All IPv4 FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 36d968425629b10f38be17787f8afe4b8afa131e 2026-05-13
FileHash-SHA1 00ff099e3cf7b548a7a0260cde8ac2f24a746da2 2026-05-13
FileHash-SHA1 124b943f6e82135b4d680df111ce121a200606dc 2026-05-13
FileHash-SHA1 143cb70aede3ba09ae54e1da55c69f0129991f48 2026-05-13
FileHash-SHA1 23a468d7277902384875d4167a81164bc2bf6e72 2026-05-13
FileHash-SHA1 42bcc743c71a9ea083c1c750a398110582796762 2026-05-13
FileHash-SHA1 5264a94271d875675336a503c94ece0baceb58c5 2026-05-13
FileHash-SHA1 54a207ed34d83d1f71d34d4ad538e8221ffba259 2026-05-13
FileHash-SHA1 5aea74bf3e70f38eb596f8002b3c02514daee4f0 2026-05-13
FileHash-SHA1 5d4ae46c14371e20d99b42cc0a683f8d5ec326ad 2026-05-13
FileHash-SHA1 68225c5613afe2174ed46e074147676b0f9a3915 2026-05-13
FileHash-SHA1 716e39bbc93fd4b394d9e6ef7c29aef1adc7dcb5 2026-05-13
FileHash-SHA1 83c6c1bb37c9071e569aa4b247e54ab763bbf5da 2026-05-13
FileHash-SHA1 8468cb5888fb383d25f9144c2b2f61c414cea3f8 2026-05-13
FileHash-SHA1 af4066ca0ae65ac63de6af60f46a9b23bb6dbfee 2026-05-13
FileHash-SHA1 bd79aec521aa9f0cec374d57692b540b7b5a6ea8 2026-05-13
FileHash-SHA1 c0979ec20b87084317d1bfa50405f7149c3b5c5f 2026-05-13
FileHash-SHA1 d6aaed67606d6dab0f652c755d3d363025f60adb 2026-05-13
FileHash-SHA1 d875d7e99f45c87e667dbebb8d8596182bdb94df 2026-05-13
FileHash-SHA1 e00293ce0eb534874efd615ae590cf6aa3858ba4 2026-05-13
FileHash-SHA1 ebddc99a00bd7a5dcaf7b73349309d970e5c69b8 2026-05-13
FileHash-SHA1 ef4b60f8162dfe20cb96dcae865a912e52459bb5 2026-05-13