Find notable cyber news and cases, enriched with sources, timelines, and signals.

Gentlemen ransomware affiliate campaign expanding toolkit and infrastructure

Campaign
First reported
Last updated
Happening score
H score 53
2 unique sources, 3 articles

Summary

Hide ▲

The Gentlemen ransomware campaign now spans a December 29, 2025 attack on Oltenia Energy Complex and later analysis of its evolving infrastructure. The company said some documents and files were encrypted and ERP, document management, email, and website services were disrupted, while activity was only partially affected and the National Energy System was not jeopardized. In April 2026, Check Point Research found a SystemBC proxy botnet of more than 1,570 hosts tied to a Gentlemen affiliate attack and said the group was expanding its toolkit and recruiting affiliates. By May 13, 2026, reporting said the gang's internal back-end database had been compromised and just over 16GB of internal data was offered for $10,000 in Bitcoin.

Related Happenings

University of Nottingham hit by cyberattack

Incident
H score68 First: 11.06.2026 10:27 Last: 11.06.2026 10:27 Sources 1

About this happening: The University of Nottingham said a well-known cybercriminal group accessed its student record system, exposing a significant amount of data affecting current students and...

Grafana Labs Says GitHub hit by cyberattack

Incident
H score70 First: 17.05.2026 10:13 Last: 17.05.2026 10:13 Sources 1

About this happening: A Grafana Labs incident was later tied to the Mini Shai-Hulud supply-chain campaign against TanStack npm packages. Grafana said an unauthorized party used a token to a...

Ghostwriter geofenced PDF spear-phishing campaign targeting Ukrainian government entities

Campaign
H score50 First: 14.05.2026 17:00 Last: 14.05.2026 17:00 Sources 1

About this happening: The Ghostwriter / FrostyNeighbor group is running a geofenced spear-phishing campaign against government entities in Ukraine, and the operation matters because it deli...

0APT and KryBit ransomware turf war forces rebuild and rebrand pressure

Threat Actor Meta
H score55 First: 28.04.2026 16:00 Last: 28.04.2026 16:00 Sources 1

About this happening: 0APT and KryBit escalated a ransomware turf war in April 2026 by leaking each other's operational data, defacing leak sites, and exposing infrastructure details that u...

The Gentlemen affiliate-driven RaaS expansion and enterprise scale-up

Threat Actor Meta
H score57 First: 21.04.2026 17:00 Last: 21.04.2026 17:00 Sources 1

How related: A rapidly expanding ransomware-as-a-service (RaaS) operation has claimed more than 320 victims, with the bulk of attacks occurring in early 2026.

About this happening: The Gentlemen ransomware-as-a-service operation is using an operator-maintained EDR-killer portfolio, led by GentleKiller, to disable security software before encrypti...

Timeline

  1. 20.04.2026 23:02 2 articles · 2mo ago

    Check Point Research finds SystemBC botnet in Gentlemen ransomware activity

    Technical Analysis Update

    Check Point Research identifies a SystemBC proxy malware botnet of more than 1,570 hosts during an investigation into a Gentlemen ransomware affiliate attack, with the victim profile suggesting corporate and organizational environments rather than opportunistic consumer targeting. The researchers say an affiliate tried to use the proxy malware for covert payload delivery, link the activity to a broader toolchain that includes SystemBC and Cobalt Strike, and note that Gentlemen ransomware is actively expanding its attack toolkit and infrastructure while recruiting new affiliates via underground forums. Check Point also publishes IoCs and a YARA rule to help defenders detect related activity.

    Show sources
  2. 29.12.2025 16:26 1 articles · 6mo ago

    Oltenia Energy Complex reports ransomware disruption

    Initial Disclosure

    Oltenia Energy Complex says a ransomware attack encrypted some documents and files and temporarily disrupted ERP systems, document management applications, the company's email service, and its website. The company says its activity was partially affected without jeopardizing the National Energy System, its IT teams started rebuilding affected systems on new infrastructure using existing backups, and the incident was reported to the National Cyber Security Directorate, the Ministry of Energy, and DIICOT.

    Show sources