SophiaX
🔍
LIVE
· New victim: Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· New victim: 3,979 new IOCs ingested in last 24h Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· 3,979 new IOCs ingested in last 24h

The Gentlemen

❔ UnknownMotivation: financialLast active: 2026-08-07First seen: 2026-04-04
5
linked CVEs
Also known as
thegentlemen
Targeted industries
Agriculture and Food ProductionBusiness ServicesConstructionConsumer ServicesEducationEnergyFinancial ServicesHealthcareHospitality and TourismManufacturingNot FoundPublic SectorTechnologyTelecommunicationTransportation/Logistics
Targeted regions
AEARATAUBEBRCACHCLCNCOCZDEDKECEGESFRGBGHGRGTHKHRIDIEINIRISITJPMXMYNINLNZOMPAPEPGPHPKPLPTPYQARUSASESGTHTNTRTWUSVEVN
The Gentlemen is a ransomware group that employs a dual-extortion strategy, encrypting sensitive files while exfiltrating critical business data to pressure victims into paying ransoms. Their operations leverage advanced techniques such as abusing legitimate utilities like PowerRun.exe for privilege escalation, using custom-built tools for defense evasion, and employing flexible encryption methods based on file size. The group targets medium to large organizations across various sectors, particularly in the Asia-Pacific region, and has demonstrated a high level of technical maturity and operational discipline. Their activities include systematic compromise of enterprise environments, mass account enumeration, and the use of encrypted channels for data exfiltration.
Source: misp_galaxy · Collected: 2026-08-08
⚡ Vulnerabilities & Exploits5 CVEs
threat_actor_cve → cves / exploits.cve_ids
CVE-2025-55182
suspected

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

CVSS 10.0
KEVransomware
CVE-2024-55591
suspected

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

CVSS 9.8
KEVransomware
CVE-2025-32433
suspected

Erlang Erlang/OTP SSH server contains a missing authentication for critical function vulnerability. This could allow an attacker to execute arbitrary commands without valid credentials, potentially leading to unauthenticated remote code execution (RCE). By exploiting a flaw in how SSH protocol messages are handled, a malicious actor could gain unauthorized access to affected systems. This vulnerability could affect various products that implement Erlang/OTP SSH server, including—but not limited to—Cisco, NetApp, and SUSE.

KEV
CVE-2025-33073
suspected

Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the victim machine to connect back to the attack system using SMB and authenticate.

KEV
CVE-2025-7771
suspected

🔍 Detection Coverage2 Sigma
Derived from linked CVEs — not a direct actor match
highvia CVE-2025-55182
Linux Suspicious Child Process from Node.js - React2Shell
linux
highvia CVE-2025-55182
Windows Suspicious Child Process from Node.js - React2Shell
windows
🧬 YaraComing soon
🛰️ Infrastructure & IOCs79
ip193.233.202.172026-08-05
ip185.45.193.1512026-08-05
ip38.110.228.432026-08-05
ip77.110.122.1372026-08-05
ip77.110.126.462026-08-05
domainresumeacceptable.com2026-08-05
domainpublisherresolution.com2026-08-05
ip77.110.122.582026-08-05
domainsimultaneouslypower.com2026-08-05
domainwiselystarting.com2026-08-05
domainitemrange.com2026-08-05
md54b690f3ce585df982a042917b82642c82026-08-05
md5bd1eaea733425cd21a51a652c429951d2026-08-05
sha160285f6776cc3ff20872feeee7f2fd0b3b04410d2026-08-05
sha19dd99bc68e60132f32fc33617deb9583c8cebb512026-08-05
sha25673955566338adffb423c3b7608792963080da780e8b7b2c2cd6b6b0cef6f217f2026-08-05
sha2567567994310a9576b1f98dc672ecfa038f1d65084315f59e3883f9b6f240000732026-08-05
sha256756c2096f54c5497110c9d854625c3ed592873e566d532077cd7adb4d10d4add2026-08-05
sha25686881b8e9d197ac2f734792de48d5dfaebe7cafb6e35d49c5dd7fe6eb697230e2026-08-05
sha256bd61c2880920bbfb86c12df439dd1ca0258a10e532433698fd029aef2a5b33f22026-08-05
sha256c7a80576fbd25057435652788591d13998da272edf627fc29d296684cefc50e52026-08-05
sha256ee6807a8abfabced22ee026e178a28da64d13cc3408e224394ff6e5782fb9e1d2026-08-05
sha256f4c87a1df04274b7497cbf9a4619b946c915cf5210b6e2eaa2fee1629f4ff1962026-08-05
sha256f609621698eaad8c4683750fe8bd0e242349be3eea408da593151ff877ed8ab62026-08-05
sha256f659681525debda69fe0865b2b27a42f684b1fda66aa7398e80b84cc765c73c72026-08-05
sha256fb94688ed37dfcb985a8a4d720230e5150956e1788d579b0a54b53a153fd2f2e2026-08-05
ip146.103.127.442026-08-05
ip185.117.72.2152026-08-05
ip38.110.228.1252026-08-05
ip38.110.228.332026-08-05
ip50.114.167.1122026-08-05
urlhttp://193.233.202.17:90012026-08-05
md5608faf58353b65c45ef9833358ac37872026-07-29
md573f0a8c3ea794a04e80c32038249f0442026-07-29
md5846dc77c1246db20d976346e0e3595022026-07-29
md5adac9984b3cc43d66a0d33079bbec2992026-07-29
md5ae0e536766788478263bf448a93816412026-07-29
md5b3e418d30312c1b2c58a791286868f422026-07-29
md5b9986a0f1f1f1a798dc3f0c59a80a1a32026-07-29
domainrsat.activedirectory.ds-lds.tools2026-07-29
md5d12a5b36dd00586cc374a1cae43efed42026-07-29
md5d2f72897e8986303d5567eb2384932b82026-07-29
md5de1522f9219497632f30f8a6e72f26b62026-07-29
md5edb1c480295250dd1a38f3aa1357deae2026-07-29
md5fdae2beb813778b4540a9977068620962026-07-29
sha1ab5ad04bb822435e5453706cd86cc001ee555aee2026-07-29
sha256cb747c0134f99d5033bac6e966864e2435a2a94244ca8e3f614f4992df93ff102026-07-29
md5c2764744dcb4b0e1db79ca1e8bf653682026-07-29
md59321a61a25c7961d9f36852ecaa86f552026-07-29
sha16afc6b04cf73dd461e4a4956365f25c1f11623872026-07-29
sha256f8965fdce668692c3785afa3559159f9a18287bc0d53abb21902895a8ecf221b2026-07-29
sha2565af1dae21425dda8311a2044209c308525135e1733eeff5dd20649946c6e054c2026-07-29
md5b6b51508ad6f462c45fe102c85d246c82026-07-29
sha196f0dbf52aed0afd43e44500116b04b674f7358e2026-07-29
sha17556ae58c215b8245a43f764f0676c7a8f0fdd1a2026-07-29
md58f0577d28c4ff5f71b149f444bfaba8e2026-07-29
sha2569ddae47ff968343a8c32a5344060257fdc08e2a7bdb9a227c8b3a584ee3c9f1e2026-07-29
md5eef8a950952696b018aa9c6da2f5d7ad2026-07-29
sha11fa071303fb846308571e64727501fb98b1c2be62026-07-29
sha2565abe477517f51d81061d2e69a9adebdcda80d36667d0afabe103fda4802d33db2026-07-29
sha2565b4f59236a9b950bcd5191b35d19125f60cfb9e1a1e1aa2e4f914b6745dde9df2026-07-29
sha168fec379f2ae76c3d2ce913f7be650cea1d069902026-07-29
md55761bd63da03686fc480245da7bd1e9f2026-07-29
md56ae7c9a7ea0b8c40a64225734f6bd01d2026-07-29
sha18468cb5888fb383d25f9144c2b2f61c414cea3f82026-07-29
sha256b67958afc982cafbe1c3f114b444d7f4c91a88a3e7a86f89ab8795ac2110d1e62026-07-29
sha256c7f7b5a6e7d93221344e6368c7ab4abf93e162f7567e1a7bcb8786cb8a183a732026-07-29
md53b46a729db7ae6af8b19711c9452194d2026-07-29
sha15aea74bf3e70f38eb596f8002b3c02514daee4f02026-07-29
sha2561af419b36a5edefef387409e2b3248c9223f7dc49a4f7b15ea095d371c3a70b22026-07-29
md510ca9a4040001560d053b7e7885c1b952026-07-29
sha1e7cc7b32d844ec6a2f41f0efbc64a0783afb56e42026-07-29
md502944c8a5535cdb5b2cbb893db2d5acf2026-07-29
md53c471ebc947cdf32240a90ffadf49b132026-07-29
md54be8bb62f0ebbcf4ce52c35ab6f794f52026-07-29
md553c616677bc7e2a0a03127f19166d0072026-07-29
md5554e699c96b332468f1ae69c1ae81ef92026-07-29
md55c3b9821fc82a9028cb63b96719509192026-07-29
md55f0b2c6d9f442754258bf4dd841c83412026-07-29
📰 Threat Intel Coverage1
Digest reports mentioning this actor (incl. aliases)
No Manners Here: The Ruthless Rise of The Gentlemen Ransomwarematched as The Gentlemen2026-07-10