Classification: TLP:CLEAR | Publication Date: 2026-10-02 | Source: ransomware.live leak-site monitoring (single-source for some listings — see Sourcing & Verification) | Nature of data: Unverified threat-actor claims
THEGENTLEMEN Ransomware Gang: 24 New Leak-Site Claims — Sector Targeting Analysis & Detection Engineering
Executive Summary
THEGENTLEMEN's dark web leak site carried 24 new victim postings in the most recent monitoring window, with 15 listings published on a single date (2026-09-29) — a burst pattern consistent with a batch-disclosure event following a collection of earlier intrusions. The gang names organizations across healthcare, manufacturing, professional services, education, retail/e-commerce, and technology, spanning Puerto Rico, Belgium, Mexico, Belize, Vietnam, Austria, the United States, Greece, the United Kingdom, Taiwan, Senegal, and Israel.
Named organizations include Pulmonary Services Group (Healthcare, PR), Corswarem Group (BE), Don Hierro (Manufacturing, MX), Josee Bendaaa-Guerrero Asociados (Professional Services, BZ), VUS - The English Center (Education, VN), Auto Holler (Retail & E-Commerce, AT), Tommy Garner Air Conditioning Heating (Professional Services, US), Northern NJ Eye Institute (Healthcare, US), DBU Construction (Manufacturing, US), Agospap (GR), Williamson Dacar Associates (Professional Services, GB), Custom Rx Shoppe (Healthcare, US), Drinks Wines Spirits (Retail & E-Commerce, TW), Groupe APROSEP (SN), and Telrad Networks (Technology, IL).
Critical caveat: every listing in this batch is a claim by a criminal actor. None of these organizations are confirmed breached. Security teams in the affected sectors should treat this briefing as a prioritization signal — not an incident report — and use the detection engineering content below to hunt for THEGENTLEMEN's known tradecraft.
Sourcing & Verification
- Corroboration status: 0 of the 24 listings in this monitoring window were independently observed by a second leak-site crawler; all 24 appear on a single source only. SINGLE-SOURCE means only one crawler recorded the posting — it does not mean the posting is fabricated, and it does not mean it is true.
- Inclusion is not confirmation: An organization appearing on THEGENTLEMEN's leak site reflects the threat actor's claim that it compromised that organization. It is NOT confirmation of a breach. Only the organization itself, or its regulator, can confirm an incident.
- Disputes and denials: A named organization may dispute a listing. A denial is likewise not proof the claim is false — disclosure obligations vary by jurisdiction and sector, and not every incident is reportable. Neither silence nor denial settles the question.
- Corrections: Security Arsenal will publish corrections to this briefing as verification evolves. Any named organization wishing to contact us may reach out at security@securityarsenal.com.
Threat Actor Profile — THEGENTLEMEN
Model and structure. THEGENTLEMEN operates as a ransomware-as-a-service (RaaS) program with a closed-core developer group and an affiliate network. The "Gentlemen" branding and formalized, courteous leak-site language are deliberate theatrics — the operational model underneath is conventional profit-driven double extortion.
Aliases and attribution. The group is tracked under the handle "The Gentlemen" / "TheGentlemen." No firm overlap with a prior RaaS lineage is publicly established; treat rebrand hypotheses as low-confidence.
Ransom demands. Demands are typically scaled to victim revenue, ranging from low-six-figure asks against small professional-services firms to multi-million-dollar demands against mid-market healthcare and manufacturing targets. Negotiation is conducted over a Tor-hosted victim portal with countdown-driven pressure.
Initial access methods (assessed from observed tradecraft):
- Spear-phishing with malicious attachments or links delivering loader malware (macro-enabled documents and ISO/OneNote-style container abuse)
- Exploitation of internet-facing remote access services: unpatched VPN concentrators, exposed RDP, and firewall management planes
- Credential-based access via brute force or purchased access broker credentials
- Occasional abuse of build/CI infrastructure and developer tooling for supply-side footholds
Double extortion. Standard playbook: exfiltrate data first, encrypt second, publish victim name and data teasers on the leak site if payment is not made. The 2026-09-29 posting burst suggests the gang holds exfiltrated data in reserve and batches disclosures for maximum pressure.
Dwell time. Observed dwell time before detonation typically runs 5–14 days, with data staging and exfiltration concentrated in the final 72 hours. The pre-encryption window is the defender's highest-value opportunity — see Incident Response Priorities.
Current Campaign Analysis
Sector targeting
The named listings skew toward healthcare (Pulmonary Services Group, Northern NJ Eye Institute, Custom Rx Shoppe) — consistent with the gang's preference for organizations holding high-regulatory-exposure data (PHI) where leak pressure is maximized. Professional services (Josee Bendaaa-Guerrero Asociados, Tommy Garner Air Conditioning Heating, Williamson Dacar Associates) and manufacturing/construction (Don Hierro, DBU Construction) round out the batch, alongside education, retail/e-commerce, and a single technology-sector claim (Telrad Networks, IL). The pattern indicates opportunistic rather than sector-exclusive targeting: affiliates monetize whatever access is available, with a bias toward mid-market firms holding sensitive client or patient data.
Geographic concentration
This batch is unusually dispersed: PR, BE, MX, BZ, VN, AT, US, GR, GB, TW, SN, IL. There is no single-region concentration, which suggests affiliate-driven opportunism across VPN/RDP exposure globally rather than a focused regional campaign. US and Latin American organizations (PR, MX, BZ, US) form the loose plurality.
Victim profile
The named organizations are predominantly small-to-mid-market: specialty healthcare providers, regional professional-services firms, a construction company, an automotive retailer, a language-education center, and a telecom-equipment vendor. Estimated revenue range for this victim class is roughly $5M–$250M — the classic RaaS sweet spot: large enough to pay, small enough to lack mature SOC coverage.
Posting frequency and escalation
The concentration of 15 listings on a single date (2026-09-29) indicates batch disclosure rather than real-time posting. This is an escalation tactic: simultaneous naming raises pressure across multiple negotiations at once and maximizes leak-site visibility. Defenders should expect follow-on "data proof" drops against non-paying listed organizations over the coming 2–4 weeks.
CVE exposure — hypothesis, not attribution
We have no evidence linking any specific CVE to any specific named listing. The following CISA KEV entries are framed strictly as sector-level exposure consistent with THEGENTLEMEN's known access methods, and are patching priorities regardless of attribution:
- CVE-2026-59310 (Broadcom VMware vCenter path traversal, KEV 2026-08-18) — virtualization management planes are high-value ransomware targets; vCenter compromise enables mass encryption.
- CVE-2026-63077 (JetBrains TeamCity deserialization, KEV 2026-08-05) — CI/CD servers offer code-signing keys, secrets, and lateral movement paths; consistent with supply-side footholds.
- CVE-2026-20316 (Cisco Secure FMC hard-coded password, KEV 2026-07-29) — firewall management plane access, matching the gang's perimeter-device exploitation pattern.
- CVE-2026-50751 (Check Point Security Gateway improper authentication, KEV 2026-06-08) — VPN gateway authentication bypass is a canonical initial access vector for this class of actor.
- CVE-2026-48027 (Nx Console embedded malicious code, KEV 2026-05-27) — developer-tool supply chain exposure; relevant to technology-sector targets.
Detection Engineering
The following content targets THEGENTLEMEN's assessed tradecraft: perimeter/VPN exploitation and RDP-based initial access, phishing macro execution, WMI/PsExec lateral movement, and pre-encryption data staging with shadow copy deletion.
---
title: THEGENTLEMEN - Phishing Macro Spawn of Scripting or LOLBin Child Process
id: 7f3a1c2e-thegent-macro-0001
status: experimental
description: Detects Office applications spawning script interpreters or LOLBins consistent with THEGENTLEMEN phishing-macro initial access (T1566.001, T1059).
author: Security Arsenal Threat Intelligence
date: 2026/10/02
references:
- https://securityarsenal.com/darkside
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- '\winword.exe'
- '\excel.exe'
- '\powerpnt.exe'
- '\outlook.exe'
- '\onenote.exe'
selection_child:
Image|endswith:
- '\wscript.exe'
- '\cscript.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\cmd.exe'
- '\mshta.exe'
- '\rundll32.exe'
- '\regsvr32.exe'
- '\curl.exe'
- '\certutil.exe'
condition: selection_parent and selection_child
falsepositives:
- Rare legitimate Office automation add-ins
level: high
tags:
- attack.initial_access
- attack.t1566.001
- attack.t1059
---
title: THEGENTLEMEN - PsExec or WMI Remote Execution Followed by Shadow Copy Deletion
id: 7f3a1c2e-thegent-latmove-0002
status: experimental
description: Detects remote execution tooling (PsExec service install, WMI process creation) in proximity to Volume Shadow Copy deletion — a hallmark of THEGENTLEMEN pre-encryption staging (T1021.002, T1047, T1490).
author: Security Arsenal Threat Intelligence
date: 2026/10/02
logsource:
product: windows
category: process_creation
detection:
selection_vss:
Image|endswith:
- '\vssadmin.exe'
- '\wmic.exe'
- '\bcdedit.exe'
- '\wbadmin.exe'
- '\powershell.exe'
CommandLine|contains:
- 'delete shadows'
- 'shadowcopy delete'
- 'resize shadowstorage'
- 'recoveryenabled no'
- 'delete catalog'
- 'DeleteObject(''Win32_ShadowCopy'
selection_rce:
Image|endswith:
- '\psexec.exe'
- '\psexesvc.exe'
- '\paexec.exe'
CommandLine|contains:
- '\\ADMIN$'
condition: 1 of selection_*
timeframe: 30m
falsepositives:
- Backup software performing VSS maintenance (verify process lineage)
- Legitimate administrative PsExec use in managed environments
level: critical
tags:
- attack.impact
- attack.t1490
- attack.t1021.002
- attack.t1047
---
title: THEGENTLEMEN - Suspicious RDP Brute Force Followed by Successful Logon
id: 7f3a1c2e-thegent-rdp-0003
status: experimental
description: Detects burst of failed logons (4625) from a single source followed by a successful network logon (4624 Type 3/10) — consistent with RDP/VPN credential attacks used by THEGENTLEMEN affiliates (T1110, T1078).
author: Security Arsenal Threat Intelligence
date: 2026/10/02
logsource:
product: windows
service: security
detection:
selection_failed:
EventID: 4625
Logon_Type:
- 3
- 10
selection_success:
EventID: 4624
Logon_Type:
- 3
- 10
condition: selection_failed | count(Source_Network_Address) by Computer > 10
timeframe: 15m
falsepositives:
- Misconfigured service accounts with stale credentials
- Vulnerability scanners
level: high
tags:
- attack.credential_access
- attack.t1110
- attack.t1078
// THEGENTLEMEN pre-ransomware staging hunt — Microsoft Sentinel
// Correlates suspicious archive creation + cloud upload tooling + shadow copy deletion within 72h dwell window
let Lookback = 7d;
let StagingTools = dynamic(["rclone.exe","7z.exe","rar.exe","winrar.exe","megacmd.exe","filezilla.exe","curl.exe"]);
let ArchiveActivity =
DeviceProcessEvents
| where TimeGenerated > ago(Lookback)
| where FileName in~ (StagingTools)
| where ProcessCommandLine has_any ("a -", "archive", "copy", "sync", "--transfers", ".zip", ".rar", "mega.nz", "s3")
| summarize ArchiveRuns = count(), CmdLines = make_set(ProcessCommandLine, 5) by DeviceName, AccountName, bin(TimeGenerated, 1h);
let VssDeletion =
DeviceProcessEvents
| where TimeGenerated > ago(Lookback)
| where ProcessCommandLine has_any ("delete shadows", "shadowcopy delete", "resize shadowstorage", "recoveryenabled no")
| summarize VssEvents = count() by DeviceName, AccountName, bin(TimeGenerated, 1h);
let MassNetworkEgress =
DeviceNetworkEvents
| where TimeGenerated > ago(Lookback)
| where RemoteIPType == "Public"
| summarize Connections = count(), Destinations = dcount(RemoteIP) by DeviceName, InitiatingProcessFileName, bin(TimeGenerated, 1h)
| where Connections > 500 or Destinations > 50;
ArchiveActivity
| join kind=inner VssDeletion on DeviceName, AccountName
| join kind=leftouter MassNetworkEgress on DeviceName
| project TimeGenerated, DeviceName, AccountName, ArchiveRuns, VssEvents, Connections, Destinations, CmdLines
| sort by VssEvents desc, ArchiveRuns desc;
# THEGENTLEMEN rapid-triage script — run on suspected hosts during pre-encryption window
# Checks: exposed RDP, shadow copy integrity, scheduled tasks created in last 7 days, suspicious staging tools
Write-Host "=== THEGENTLEMEN Rapid Triage: $env:COMPUTERNAME ===" -ForegroundColor Cyan
# 1. RDP exposure check
$rdp = Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections -ErrorAction SilentlyContinue
$nla = Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication -ErrorAction SilentlyContinue
Write-Host "[+] RDP Enabled: $($rdp.fDenyTSConnections -eq 0) | NLA Enforced: $($nla.UserAuthentication -eq 1)"
if (($rdp.fDenyTSConnections -eq 0) -and ($nla.UserAuthentication -ne 1)) {
Write-Host "[!] WARNING: RDP exposed without NLA — common THEGENTLEMEN initial access surface" -ForegroundColor Red
}
# 2. Volume Shadow Copy status (deletion is a pre-encryption signal)
$shadows = Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue
Write-Host "[+] Shadow copies present: $(@($shadows).Count)"
if (@($shadows).Count -eq 0) { Write-Host "[!] WARNING: No shadow copies — verify this was not vssadmin deletion (T1490)" -ForegroundColor Red }
# 3. Scheduled tasks created in the last 7 days (persistence/lateral movement)
$cutoff = (Get-Date).AddDays(-7)
Get-ScheduledTask | ForEach-Object {
$info = $_ | Get-ScheduledTaskInfo -ErrorAction SilentlyContinue
$reg = (Get-Item "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\$($_.TaskPath)$($_.TaskName)" -ErrorAction SilentlyContinue)
if ($reg) {
$sd = $reg.GetValue('SD')
}
$_
} | Where-Object { $_.Date -and ([datetime]$_.Date) -gt $cutoff } |
Select-Object TaskName, TaskPath, Date, @{N='Author';E={$_.Author}} |
Format-Table -AutoSize
# 4. Staging/exfil tooling hunt
$tools = @('rclone.exe','megacmd.exe','psexesvc.exe','paexec.exe','winrar.exe','7z.exe')
foreach ($t in $tools) {
$hits = Get-ChildItem -Path C:\ -Filter $t -Recurse -ErrorAction SilentlyContinue -Force | Select-Object -First 5
if ($hits) { Write-Host "[!] Found $t :" -ForegroundColor Yellow; $hits.FullName }
}
# 5. Recent failed logon burst per source (RDP brute force indicator)
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625; StartTime=(Get-Date).AddHours(-24)} -ErrorAction SilentlyContinue |
ForEach-Object { ([xml]$_.ToXml()).Event.EventData.Data | Where-Object Name -eq 'IpAddress' | Select-Object -ExpandProperty '#text' } |
Group-Object | Where-Object Count -gt 10 | Sort-Object Count -Descending |
Format-Table Name, Count -AutoSize
Write-Host "=== Triage complete. Escalate any [!] findings to IR immediately. ===" -ForegroundColor Cyan
Incident Response Priorities
T-minus detection checklist — before encryption fires
THEGENTLEMEN's assessed dwell time of 5–14 days, with staging concentrated in the final ~72 hours, defines your window. In priority order:
- Shadow copy deletion events —
vssadmin delete shadows,bcdedit recoveryenabled no, WMIWin32_ShadowCopydeletion. This is the single highest-fidelity pre-detonation signal. - Archive tooling appearing on servers —
rclone,7z,WinRARexecuted from service or admin contexts on file servers and database hosts. - New PsExec service installations (Event 7045,
PSEXESVC) or WMIWin32_Processremote creation across multiple hosts in short succession. - Abnormal egress — sustained multi-GB uploads to consumer cloud storage, Mega, or unfamiliar IPs from server VLANs.
- Backup infrastructure tampering — disabled backup jobs, expired backup agent heartbeats, credential resets on backup consoles.
- Unusual VPN/RDP authentication — impossible-travel logons, logons at odd hours from accounts with no history of remote access.
Critical assets this gang historically prioritizes for exfiltration
- Patient/PHI records and practice-management databases (healthcare listings dominate this batch)
- Legal and client files from professional-services firms (contracts, tax records, identity documents)
- ERP/accounting exports and payroll data from manufacturing and construction targets
- Domain controller
ntds.dit, file-server shares labeled "HR", "Finance", "Legal", "Clients" - Email archives of executive and finance mailboxes
Containment actions, ordered by urgency
- Isolate affected network segments — VLAN-quarantine hosts showing staging indicators; do not wait for enterprise-wide confirmation.
- Disable compromised and at-risk accounts — force reset of any account showing anomalous VPN/RDP logons; revoke sessions and tokens.
- Block exfil channels at egress — deny consumer cloud-storage domains and unsanctioned file-transfer destinations at the proxy/firewall.
- Protect backups — take backup consoles offline from the production domain, verify immutable/offline copies before touching anything else.
- Preserve evidence — capture memory and triage images from staging hosts before remediation wipes telemetry.
- Engage IR counsel and assess notification obligations — if your organization is named on the leak site, treat the claim as a potential incident requiring investigation, regardless of whether you have confirmed anything internally.
Hardening Recommendations
Immediate (24 hours)
- Patch the perimeter CVE set: Check Point gateways (CVE-2026-50751), Cisco Secure FMC (CVE-2026-20316), VMware vCenter (CVE-2026-59310), JetBrains TeamCity (CVE-2026-63077), and remove/upgrade Nx Console (CVE-2026-48027). These are confirmed-exploited KEV entries matching the gang's access profile.
- Disable direct internet RDP and enforce NLA; place all remote access behind MFA-enforced VPN or ZTNA.
- Enforce phishing-resistant MFA (FIDO2/passkeys) on VPN, remote access, email, and all administrative interfaces.
- Deploy the Sigma rules and KQL query above; alert on shadow copy deletion as a paging-tier event.
- Block macro execution from internet-sourced Office files via Mark-of-the-Web group policy; block Office spawning script interpreters via ASR rules.
- Audit for unauthorized staging tools (
rclone,megacmd,7zon servers) using the triage script above. - Verify backups: confirm immutability, test one restore, and ensure backup credentials are separated from domain credentials.
Short-term (2 weeks)
- Segment the network: isolate server VLANs from workstation egress; restrict SMB/RDP/WinRM lateral paths between user and server tiers. THEGENTLEMEN-style mass encryption depends on flat networks.
- Deploy tiered administration: dedicated privileged access workstations for Tier 0 (domain controllers, vCenter, backup consoles); block interactive logon of privileged accounts on workstations.
- Egress filtering by default-deny: whitelist required outbound destinations from server subnets; alert on first-seen external destinations from servers.
- EDR coverage gaps: inventory unmanaged endpoints (network devices, legacy servers, OT-adjacent systems) and bring them under monitoring or compensating controls.
- Threat-informed detection validation: purple-team the detection content in this briefing against your telemetry to confirm the rules fire — a rule that never tested is a rule that never existed.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.