Enterprise ransomware operations increasingly prioritize identity compromise, lateral movement, and data theft over immediately visible encryption. In Q4 2025, attackers used legitimate administration tools including RDP, SSH, PSExec, and native management utilities for lateral movement in 65% of observed cases; confirmed data exfiltration occurred in 94% of incidents, while encryption was confirmed in 68%. Defense evasion targeted endpoint protections, identity telemetry, and logging, and credential abuse increasingly relied on reuse, replay, inherited access, and trusted relationships. Cloud and SaaS environments have further reduced defender visibility and enabled faster, quieter exfiltration.
Stolen data is also becoming a durable criminal asset rather than a one-time leak: at least 10 extortion groups were reportedly analyzing, indexing, categorizing, and reselling exposed enterprise data by July 2026, using analysts, scripts, machine learning, or LLM-assisted workflows. The compromise of The Gentlemen's Rocket.Chat infrastructure exposed a structured affiliate operation targeting Fortinet VPNs, using CVE-2024-55591, stolen credentials, proxy-chained movement, custom G-BOT infrastructure, repurposed Velociraptor, and AI tools for negotiation and data triage. Follow-on artifacts showed rclone, Synology NAS, and MEGA-based exfiltration and potential Active Directory exposure, underscoring the need to revoke exposed credentials comprehensively, hunt for data-transfer tooling, harden repositories, and monitor stolen data for resale and downstream social-engineering or supply-chain abuse.

TTPs, infrastructure, and targeting history in one profile.
11 events from the most recent confirmed update back to the earliest known activity.
Lab-1 assessed that at least 10 ransomware or data-extortion groups were indexing or analyzing stolen data by July 2026, compared with one observed group in 2024. The groups used human analysis, AI/LLM-assisted workflows, or scripted extraction to increase extortion leverage and enable resale.
The n345 user released the alleged The Gentlemen archive freely on CryptBB. The archive exposed 3,366 messages from 22 Rocket.Chat rooms, screenshots, and operational files.
A user using the name n345 offered alleged The Gentlemen data for sale on PwnForums for $10,000 in Bitcoin.
The Gentlemen confirmed that part of its Rocket.Chat infrastructure had been compromised and that a leaked Rocket.Chat password was genuine. It claimed its control panel, blog, lockers, and other core components were unaffected.
Hosting provider 4VPS.SU disclosed that its website and client billing system had been breached through a proxy-server swap and phishing-redirection incident. The Gentlemen later attributed exposure of part of its Rocket.Chat infrastructure to this breach.
A Synology NAS at 193.228.128.2 received an rclone connection over SFTP on TCP port 2222, reportedly using the account d0wnloAd1. The infrastructure was later assessed as part of an rclone-to-NAS-to-MEGA exfiltration workflow.
The group migrated from Mattermost to a self-hosted Rocket.Chat instance on Tor in mid-November 2025. The subsequently leaked chat corpus covered activity from November 2025 through late April 2026.
The Gentlemen made its first public post to its data-leak site on September 9, 2025.
Coveware observed lateral movement in 65% of cases and confirmed data exfiltration in 94% of ransomware incidents during Q4 2025. Attackers commonly abused legitimate administration tools and reused or inherited credentials, while encryption was confirmed in 68% of incidents.
The Russian-speaking ransomware-as-a-service operation known as The Gentlemen emerged in July or August 2025.
A follow-on package, reportedly posted by an unverified user named n7778, allegedly contained material exfiltrated from infrastructure used by Zeta/The Gentlemen. Artifacts included a MEGA GDPR export, Synology NAS shadow data, evidence of rclone and MEGA staging activity, and alleged victim data including domain-controller backup metadata.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 36 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
ransom-isac.org
Open sourceransom-isac.org
Open sourceransom-isac.org
Open sourcecoveware.com
Open sourcesophos.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.