PULSE NAME
Thus Spoke…The Gentlemen
WHITE The Gentlemen AlienVault 2026-05-13 Modified: 2026-05-14
119
IOCs
HIGH VOLUME
On May 4th, 2026, The Gentlemen RaaS administrator acknowledged that an internal backend database called Rocket had been leaked, exposing nine accounts including zeta88, the program's effective administrator. The leak revealed internal discussions detailing initial access methods through Fortinet and Cisco edge appliances, NTLM relay, and credential logs, along with the group's role divisions and toolsets. Evidence shows evaluation of CVEs including CVE-2024-55591, CVE-2025-32433, and CVE-2025-33073. Leaked ransom negotiations showed a successful payment of 190,000 USD. The group reused stolen data from a UK software consultancy to attack a Turkish company, employing dual-pressure tactics during negotiations. Analysis of ransomware samples identified eight distinct affiliate TOX IDs, indicating the administrator actively participates in infections alongside managing the RaaS program.
Indicators of Compromise (27 / 119 total)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 00ff099e3cf7b548a7a0260cde8ac2f24a746da2 2026-05-13
FileHash-SHA1 124b943f6e82135b4d680df111ce121a200606dc 2026-05-13
FileHash-SHA1 143cb70aede3ba09ae54e1da55c69f0129991f48 2026-05-13
FileHash-SHA1 23a468d7277902384875d4167a81164bc2bf6e72 2026-05-13
FileHash-SHA1 2cd15d5d4cc58d06cfb6be5eabc681925d0ce5ce 2026-05-13
FileHash-SHA1 42bcc743c71a9ea083c1c750a398110582796762 2026-05-13
FileHash-SHA1 4424138cf5a6770ab54132208a6bfed7ceb32beb 2026-05-13
FileHash-SHA1 5264a94271d875675336a503c94ece0baceb58c5 2026-05-13
FileHash-SHA1 54a207ed34d83d1f71d34d4ad538e8221ffba259 2026-05-13
FileHash-SHA1 5aea74bf3e70f38eb596f8002b3c02514daee4f0 2026-05-13
FileHash-SHA1 5d4ae46c14371e20d99b42cc0a683f8d5ec326ad 2026-05-13
FileHash-SHA1 68225c5613afe2174ed46e074147676b0f9a3915 2026-05-13
FileHash-SHA1 716e39bbc93fd4b394d9e6ef7c29aef1adc7dcb5 2026-05-13
FileHash-SHA1 83c6c1bb37c9071e569aa4b247e54ab763bbf5da 2026-05-13
FileHash-SHA1 8468cb5888fb383d25f9144c2b2f61c414cea3f8 2026-05-13
FileHash-SHA1 8cdfedf9416ef9e50548f02e5dfa5dd5aa38c586 2026-05-13
FileHash-SHA1 908b39041bab41aef7b2d4d7ffdb72bb5b1e3437 2026-05-13
FileHash-SHA1 9e951cf2f868b71aaaa05966d8eb96d333b80106 2026-05-13
FileHash-SHA1 af4066ca0ae65ac63de6af60f46a9b23bb6dbfee 2026-05-13
FileHash-SHA1 bd79aec521aa9f0cec374d57692b540b7b5a6ea8 2026-05-13
FileHash-SHA1 d6aaed67606d6dab0f652c755d3d363025f60adb 2026-05-13
FileHash-SHA1 d875d7e99f45c87e667dbebb8d8596182bdb94df 2026-05-13
FileHash-SHA1 de8e1859412cc7b0ea81d7c6461267b079059dda 2026-05-13
FileHash-SHA1 ebddc99a00bd7a5dcaf7b73349309d970e5c69b8 2026-05-13
FileHash-SHA1 ef4b60f8162dfe20cb96dcae865a912e52459bb5 2026-05-13
FileHash-SHA1 f1ca6f9eb8f41dd0940683747d8926ac485ae40e 2026-05-13
FileHash-SHA1 f1025bb2f147c01742f263bc0b8d462af9728a22 2026-05-13