Logo
News Ababil
Explore
Global Intel (English)
Global Intel (English)VOICE
Bengali (বাংলা)
Spanish (Español)VOICE
French (Français)VOICE
German (Deutsch)
Arabic (العربية)
Hindi (हिन्दी)VOICE
Chinese (中文)
Japanese (日本語)
Russian (Русский)
SYS_NODE: ONLINE // Cyber Security

Inside The Gentlemen ransomware: Who Is Steering the Fast‑Growing RaaS Outfit?

DECRYPTED BY: Kaelen Frost | TIMESTAMP: 2026-06-18 T 08:46:26 Z | [ 2 MIN READ ]
Inside The Gentlemen ransomware: Who Is Steering the Fast‑Growing RaaS Outfit?
2 Min Read
Share

The Gentlemen ransomware has vaulted to the second‑largest RaaS operation by victim count, luring seasoned hackers with a ↑ 90% affiliate cut. Security firm Check Point reports 332 disclosed victims since mid‑2025 and more than 240 in 2026 alone. The group exploits internet‑facing assets, hijacks VPNs and firewalls, and encrypts whole networks within hours. According to the same researchers, the mastermind behind the operation hides behind the monikers Zeta88 and Hastalamuerte, managing the locker, payments and the RaaS panel.

The Gentlemen ransomware: Operational Blueprint

Check Point notes the gang targets exposed VPN gateways, often brute‑forcing Fortinet SSL‑VPN credentials before deploying the encryptor. Once inside, the malware spreads laterally, encrypting file systems at machine‑wide speed.

“Their 90/10 revenue split is a magnet for operators abandoning rival RaaS schemes,” a Check Point analyst told Reuters.

Identifying the Administrator

Open‑source intelligence traced the alias Hastalamuerte to a Russian‑English speaker registering on Breachforums from Izhevsk in January 2025. The same individual later appeared as Zeta88 on the English‑language forum Breached in August 2022, using the same IP block. Email traces (hastalamuerte1488@protonmail.com) link to an Apple‑associated account and a phone number ending in 04, which Constella Intelligence matched to Alexander Andreevich Yapaev, a 36‑year‑old marketing director at Uralenergo Udmurtia.

Further digging revealed the ProtonMail address is tied to a private GitHub profile “SantaMuerte,” where the user follows malware‑tool repositories. On Telegram, the handle @hastalamuerte18 carries the unique ID 30907522, confirming cross‑platform consistency.

The admin supplies affiliates with initial access bundles, predominantly harvested Fortinet credentials, and leverages AI to refine the ransomware payload and post‑exploitation scripts, as detailed in a recent Bloomberg briefing. The same report highlighted the group’s tolerance for sloppy OPSEC among newcomers, explaining why early forum posts expose rudimentary training attempts – a pattern mirrored across many Russian cybercrime outfits, especially during the pandemic era.


Intel provided by Kaelen Frost (Lead Cybersecurity Analyst).

Global Data Feed

More from this Intel

Issabel Framework Flaw Triggers Remote Code Execution – Critical CVE‑2026‑89026 Exploited

Issabel Framework Flaw Triggers Remote Code Execution – Critical CVE‑2026‑89026...

Sep 17, 2026
Iranian Hackers Deploy CHOSEN BRICK Malware to Spy on Dissidents Worldwide

Iranian Hackers Deploy CHOSEN BRICK Malware to Spy on Dissidents...

Sep 16, 2026
Radaris Domains Seized in New Jersey Privacy Showdown

Radaris Domains Seized in New Jersey Privacy Showdown

Sep 16, 2026
Shai-Hulud malware hijacks AI coding assistant, infects 100+ repos in massive supply‑chain breach

Shai-Hulud malware hijacks AI coding assistant, infects 100+ repos in...

Sep 16, 2026
Conquering Career Anxiety in a Turbulent Tech Market

Conquering Career Anxiety in a Turbulent Tech Market

Sep 16, 2026
AI-Powered Scam Protection: McAfee+ Launches Discounted Plan to Block Deepfake Threats

AI-Powered Scam Protection: McAfee+ Launches Discounted Plan to Block Deepfake...

Sep 15, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.