discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm

PRODAFT says The Gentlemen ransomware has claimed 478 victims since March 2025 and can spread rapidly across networks.

By Ravie Lakshmanan·Jun 11·thehackernews.com·2 min read

Intelligence analysis by GPT-5.4 Mini

The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm
Image: thehackernews.com

A new report says The Gentlemen has evolved from a RaaS affiliate into its own operation, with AI-assisted tooling, aggressive affiliate support, and worm-like propagation. The group targets enterprise environments through exposed edge devices and stolen credentials.

Why it matters

This is a detailed look at a fast-moving ransomware crew that is already producing a large victim count and using flexible propagation tactics. Security teams need the tradecraft details to prioritize defenses around edge devices, identity, and endpoint controls.

The Gentlemen is like a break-in crew that keeps changing tools and routes to get into offices. Once inside, it can lock doors, copy files, and even spread from room to room like a fast bug.

Analysis

What PRODAFT says

PRODAFT tracks the operation as Phantom Mantis and says it was led by a Russian-speaking actor it labels LARVA-368. The report says the group first worked as an affiliate using multiple ransomware-as-a-service programs, then shifted in July 2025 into its own independent partnership program.

The article says The Gentlemen has claimed 478 victims since March 2025, based on Ransomware.Live data. It also notes that the group accounted for 10% of ransomware activity in April 2026, which points to a significant operational footprint.

How it operates

The group is described as enterprise-focused, entering through vulnerable internet-facing services or stolen credentials. NCC Group says the attackers adapt during intrusions, including by manipulating GPOs, compromising privileged accounts, and using custom methods to get around endpoint protections.

The report says the group provides support through The Gentlemen IM and other messaging platforms, and that it offers five ransomware builds for Windows, Linux, ESXi, Windows XP+, and LVM. Affiliates are reportedly offered a 90/10 split, which helps explain the group's recruitment appeal.

Defensive implications

The article highlights edge devices such as VPN appliances, firewalls, Cisco gear, and Fortinet FortiGate as key entry points. It also says the attackers use tools for AD discovery, certificate abuse, privilege escalation, file-share discovery, and defense evasion, plus attempts to disable Microsoft Defender and clear Windows event logs.

PRODAFT says the group asks for at least 1GB of exfiltrated victim data before granting affiliate panel access, a safeguard meant to keep researchers and law enforcement from posing as affiliates. The overall picture is of a well-supported ransomware operation that combines access, extortion, and broad propagation tactics.

Key points

  • PRODAFT says The Gentlemen has claimed 478 victims since March 2025.
  • The group reportedly moved from using other RaaS programs to running its own operation in July 2025.
  • Attackers are said to enter through exposed services or stolen credentials and then use tools for privilege escalation and defense evasion.
  • The article says the group can spread like a worm and offers multiple ransomware builds across Windows, Linux, ESXi, XP+, and LVM.
  • Only about 13% of victims are in the U.S.; many victims are in Thailand, the U.K., Brazil, Germany, and India.
The Upside

If defenders act on these findings, organizations can tighten protection around VPNs, firewalls, and identity systems before the group gets in. The detailed breakdown of tools and tactics also gives security teams better signals to detect and block similar attacks sooner.

The Downside

If the group keeps recruiting affiliates and refining its tooling, it could continue scaling attacks across many sectors and regions. Its worm-like spread and defense-evasion steps could make intrusions harder to contain once an initial foothold is gained.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityransomwarecybercrimethreat-intelligencerussiaunited-states

Author

Ravie Lakshmanan

Intelligence analysis by

GPT-5.4 Mini

Published

Jun 11, 2026

Source

thehackernews.com

Share

Topics

securityransomwarecybercrimethreat-intelligencerussiaunited-states

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…