LIVE · cybersecurity feed
Live wire
ransomware

Who Runs the Ransomware Group ‘The Gentlemen?’

A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of

zeroday.news · 52d ago

A rapidly growing ransomware-as-a-service operation known as The Gentlemen has become the second most active ransomware group by victim count, according to security firm Check Point Software. The group has attracted skilled hackers by offering affiliates a generous 90 percent share of ransom payments, a higher split than the industry standard. Since its inception in mid-2025, The Gentlemen has claimed at least 332 victims, with over 240 occurring in 2026 alone.

The Gentlemen's operational model focuses on exploiting internet-facing devices, such as VPNs and firewalls, as initial entry points. Once inside a network, the group is known to move quickly, encrypting entire systems within hours. Check Point researchers have identified the administrator of The Gentlemen, who operates under the nickname Zeta88 on Russian-language cybercrime forums, as the same individual previously known as Hastalamuerte. This person is responsible for assembling the ransomware and its management panel, handling payments, and ultimately receives the 10 percent commission from all ransoms.

Cyber intelligence firm Intel 471 has tracked the user Hastalamuerte across numerous cybercrime forums since 2019, noting registration on platforms including Exploit, Breachforums, Ramp_V2, BHF, Raidforums, and Nulled. In January 2025, Hastalamuerte registered on Breachforums from an internet address located in Izhevsk, Russia. Separately, the username Zeta88 signed up for the English-language forum Breached in August 2022, also originating from Izhevsk.

Further investigation by Intel 471 revealed that Hastalamuerte registered on Raidforums in 2020 using the email address hastalamuerte1488@protonmail.com. The inclusion of "1488" in the email address is noted as a combination of symbols often associated with white supremacy. An analysis of this email address by the open-source intelligence service Epieos linked it to an Apple account and a phone number ending in 04. Epieos also found that the Protonmail address was connected to a private GitHub account under the username SantaMuerte, which, despite being private, showed activity related to the development of malware and exploits.

In April 2020, Hastalamuerte indicated on the Nulled forum that they could be reached via Telegram at the username @hastalamuerte18. Threat intelligence company Flashpoint identified this username as corresponding to a unique Telegram ID number. The breach tracking service Constella Intelligence reported that Hastalamuerte's Telegram ID is also linked to another username, bu4vs, and a Russian phone number.

Cross-referencing this phone number in Constella's data revealed multiple records from compromised Russian government databases. These records assigned the number to Alexander Andreevich Yapaev, a 36-year-old individual from Izhevsk. Constella's findings indicate that this phone number was used to create an account on the Russian social media platform Pikabu under the name 4apai18. Additionally, Mr. Yapaev has reportedly used variations of the surname Ivanov or Chapaev when signing up for various websites.

Intel 471's search for cybercrime forum members using the nickname SantaMuerte uncovered an account created in 2020 on the Russian hacking forum Codeby. This user initially registered on Codeby with the username Alexandr 4apaev. Constella Intelligence found that Mr. Yapaev frequently used the email address bu4vs@mail.ru. Epieos connected this email address to a LinkedIn profile for Alexander Yapaev, who lists his position as head of B2B marketing at Uralenergo Udmurtia, a significant supplier of electrotechnical and lighting products in Russia. Mr. Yapaev did not respond to requests for comment.

The article suggests that the relative lack of anonymity among some Russian cybercriminals may stem from a gradual immersion into the scene, a general tendency for the Russian government to either co-opt or ignore cybercriminal activity within its borders as long as it does not target Russian entities, and early-career operational security mistakes. Early posts by Hastalamuerte from 2019-2020 indicate a less experienced hacker learning the trade.

An update from threat research group PRODAFT corroborates these findings, stating with high confidence that the administrator (Zeta88/Hastalamuerte) directly supplies affiliates with initial access, primarily through Fortinet SSL-VPN credentials obtained via brute-force attacks or from the group's own leak database. PRODAFT also reported that the administrator is employing artificial intelligence for developing and maintaining ransomware and associated tools, as well as for post-exploitation activities.

ransomware
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.

vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]