CiberLATAMbywhalemate

The Gentlemen ransomware hits LATAM

The Gentlemen grew into a double-extortion RaaS in 2026, targeting LATAM with Fortinet, RDP, and attacks in Colombia, Peru

Whalemate Labs · AI-assisted researchAug 17, 202639 min read

The Gentlemen went from an emerging ransomware operation to one of 2026’s most prolific actors in less than a year. Consolidated reporting describes it as a human-operated ransomware-as-a-service group tracked by Microsoft Threat Intelligence as Storm-2697, which surfaced publicly in mid-2025 and opened its affiliate program in September of that year. Its expansion was rapid: multiple intelligence vendors placed it among the world’s most active groups in the second quarter of 2026, with a growing concentration of victims on its leak site and a double-extortion model built around data theft, file encryption, and pressure through publication threats.

The group’s intrusion chain was notably consistent. Initial access repeatedly relied on edge vulnerabilities, especially Fortinet FortiGate and FortiOS, though Citrix NetScaler ADC, SonicWall SSL VPN, and RMM platforms such as ConnectWise ScreenConnect also appeared. Stolen or purchased credentials, phishing with macros, and exposed RDP were added to the mix. Once inside, The Gentlemen showed multi-day persistence, network reconnaissance, defense tampering, shadow copy deletion, and exfiltration before encryption. On the technical side, the ransomware was written in Go, obfuscated with Garble, with variants for Windows, Linux, BSD, NAS, and ESXi, and the use of XChaCha20 and Curve25519 in several observed families. BYOVD drivers such as PoisonX and anticheatG13.sys also appeared, aimed at killing security processes before encryption began.

In Latin America, the most visible case was Ecopetrol in Colombia. The company detected irregular access on July 17, 2026, with information extracted from about 3,300 accounts and data stored in the cloud for 15 group companies. The Gentlemen claimed more than 1 TB and 65 million documents were exfiltrated, although the exact volume was not independently verified. Following the incident, ColCERT issued high-risk alerts and reinforced guidance on Fortinet FortiGate patching and multifactor authentication for remote access. Then came Oldelval in Argentina, the Municipality of San Luis in Peru, Advanced Marketing in Mexico, Grupo Minero Las Cenizas in Chile, and Intranet Gov Brasil, with varying levels of public confirmation, but all following the same operating pattern: perimeter intrusion, rapid exfiltration, leak threats, and negotiations under pressure.

The regional picture that emerges is of an operation that no longer depends only on victim volume, but on industrializing initial access and turning exposed appliances, leaked credentials, and poorly managed remote services into a scalable monetization path. The Gentlemen is now a case study in the convergence of ransomware, access brokering, and multi-stage extortion across government, energy, services, and manufacturing organizations in the region.

Executive summary

The Gentlemen became one of the most active ransomware operations in the criminal market in 2026, with metrics that consistently place it among the highest-volume actors in claimed victims. Consolidated reporting describes it as a human-operated ransomware-as-a-service operation, tracked by Microsoft Threat Intelligence as Storm-2697, with a formal shift to an affiliate model in September 2025. Through 2026, it went from a recent arrival to large-scale activity, with hundreds of victims listed on its leak site and a steady rise in published claims.

The most stable feature of the campaign is double extortion. In practice, The Gentlemen enters corporate networks, exfiltrates sensitive data, encrypts critical systems, and then threatens to publish the stolen information if payment is not made. Several analyses added that in some cases the group escalated pressure further, using countdown timers on its leak site, partial document releases, and, in some reports, DDoS threats. That puts it at a more aggressive operational tier than classic ransomware focused only on downtime.

The technical expansion was just as clear. The group used a Go-based encryptor obfuscated with Garble, with builds for Windows, Linux, BSD, NAS, and ESXi, and with algorithms such as XChaCha20 and Curve25519 in different related families. Around that core, the operation added evasion and defense-disruption techniques, including shadow copy deletion, PsExec and WMI abuse, antivirus disabling, and BYOVD-compatible mechanisms. In practical terms, this means an intrusion chain built around persistence, reconnaissance, and the removal of barriers before encryption.

Its target profile is also consistent. Sources cite sectors including manufacturing, healthcare, finance, construction, energy, retail, technology, education, insurance, and government. Geographically, the consolidated evidence shows claims across North America, South America, Europe, Africa, and Asia, with visible presence in Mexico, Colombia, Peru, Chile, Argentina, and Brazil. This is not just a global actor, but one that found a concrete opportunity surface in Latin America, especially where exposed services, weak credentials, unpatched VPNs, and low tolerance for disruption converge.

On the defensive side, the most repeated signal is that The Gentlemen does not depend on a single vector. It combines edge exploitation, purchased access, phishing, exposed RDP, and abuse of remote administration tools. That mix, combined with the speed of pre-encryption exfiltration, makes detection based only on the moment ransomware detonates arrive too late. The real hunting window comes earlier, in VPN telemetry, bursts of mass file reads, unusual admin sessions, and the appearance of reconnaissance and defense-manipulation tools.

Context and background

The Gentlemen appears in the material as an operation that emerged in mid-2025, with early references ranging between July and August of that year. ManageEngine, FortiGuard, Mallory.ai, DysruptionHub, BlackFog, Halcyon, Ransomware.live, and other profiles agree that it is a RaaS operation, with a gradual shift from a closed phase to a more public affiliate model. Some reports place that formal opening in September 2025. Others note that its origin may lie in the evolution of ArmCorp, a former Qilin affiliate, reinforcing the reading of an ecosystem under fragmentation and of operators with prior experience moving between groups.

That background matters for two reasons. First, it explains how quickly the group was able to scale. Second, it helps explain why its playbook mixes traditional ransomware tactics with more sophisticated exfiltration, C2, and evasion infrastructure. Rather than a static toolkit, the material shows an operation that adapts its chain to each victim’s exposed surface, but always around the same business logic: monetize access, leak data, and force negotiations.

The material also shows that the group did not rely on a single malware family. There are references to a Go-based encryptor obfuscated with Garble, a multiplatform toolkit for Windows, Linux, ESXi, BSD, and NAS, additional lockers, self-propagating variants, and evasion modules using malicious drivers. Among the most consistent observations are the use of GentleKiller, PoisonX3.sys, PoisonX4.sys, and anticheatG13.sys, all designed to weaken security solutions before encryption is executed.

The Gentlemen trend, 2025-20262025-07Firstappearance2025-09Shift toaffiliates2026-03Public tracking2026-07Ecopetrol andpeak2026-0825 victims new2026-08IoCs anddrivers
The Gentlemen Trend — Milestones from its emergence in 2025 through the rise in victims in 2026.

Key facts table

Date Event Source Confidence
2025-07 to 2025-09 The Gentlemen emerges as a RaaS operation and shifts to affiliates ManageEngine, BlackFog, Halcyon, DysruptionHub Confirmed
2026-03 From mid-March, IntelFusions begins tracking the group’s leak site IntelFusions Confirmed
2026-04 BlackFog and BankInfoSecurity report hundreds of named victims on leak sites BlackFog, BankInfoSecurity Confirmed
2026-06 Check Point and other firms place the group among the quarter’s most prolific actors Check Point Research, The Insurer, Mallory.ai Confirmed
2026-07-09 Attack on Ecopetrol, with exfiltration and irregular access to cloud environments Ransomware.live, Infobae, DataEnforce Confirmed
2026-07-16 Peak activity, with 17 posts attributed to The Gentlemen in a single day Scrutex Confirmed
2026-07-18 Ecopetrol is added to the leak site and ColCERT issues a public alert Scrutex, El Colombiano, IntelFusions Confirmed
2026-07-23 Oldelval is listed by The Gentlemen GalaxyWarden, Ransomware.live Confirmed
2026-07-24 Advanced Marketing appears in the group’s public postings GalaxyWarden, Dexpose, HackerFeeds Confirmed
2026-07-31 San Luis municipality and Grupo Minero Las Cenizas appear on the leak site GalaxyWarden, Dexpose, Hookphish Confirmed / Unconfirmed claim depending on the case
2026-08-04 Mallory.ai and others report new victims in the United States and elsewhere Mallory.ai Confirmed
2026-08-07 Intranet Gov Brasil is added to the leak site, without official confirmation GalaxyWarden, RecentBreaches Unconfirmed claim
2026-08-10 to 2026-08-17 Multiple reports consolidate The Gentlemen as a hyper-prolific actor and publish IoCs Security Arsenal, Ransomware.live, Halcyon, RST Cloud Confirmed

Operation timeline

Date Event Actor/vector Verified source
2025-07 First public appearance of the actor Operation begins BlackFog
2025-08 Halcyon places the group’s appearance in August 2025 Multiplatform toolkit Halcyon
2025-09 Formal move to an affiliate model RaaS with partner program ManageEngine, DysruptionHub
2026-03-15 approx. IntelFusions begins public tracking of the leak site Leak site and victimology IntelFusions
2026-04 More than 320 victims listed in public counts Leak site, cumulative metrics DysruptionHub, BlackFog
2026-06 The group rises to among the most active of the quarter Victim postings Check Point Research, The Insurer, Mallory.ai
2026-07-09 Intrusion at Ecopetrol Irregular access, exfiltration Infobae, Ransomware.live, DataEnforce
2026-07-16 Peak of 41 posts on leak sites, 17 attributed to The Gentlemen Leak site, double extortion Scrutex
2026-07-18 Ecopetrol enters the leak site, ColCERT issues an alert Public extortion Scrutex, El Colombiano
2026-07-23 Oldelval is posted by the group Leak site, leak threat GalaxyWarden, Dexpose
2026-07-24 to 2026-07-25 Advanced Marketing is listed and publicly claimed Phishing or RDP, rapid exfiltration GalaxyWarden, Dexpose, HackerFeeds
2026-07-31 San Luis municipality, Las Cenizas, and other claims join the leak site Public extortion, unconfirmed claims GalaxyWarden, Hookphish, Ransomware.live
2026-08-04 New victims in the United States and other markets Expanding campaign Mallory.ai
2026-08-06 Peaks of 14 victims in 24 hours Mass leak site operation Security Arsenal
2026-08-07 Intranet Gov Brasil appears as an unconfirmed claim Actor leak site GalaxyWarden, RecentBreaches
2026-08-10 to 2026-08-17 Publication of IoCs, drivers, hashes, and telemetry Defense and detection Halcyon, Ransomware.live, Cynet, RST Cloud

Attack chain and TTPs

The operational pattern that emerges from the research is consistent and not improvised. Initial access usually comes through the perimeter, not through an isolated endpoint. Cyware identifies three recurring vectors, Citrix NetScaler ADC (CVE-2025-5777), SonicWall SSL VPN (CVE-2024-40766), and Fortinet FortiOS (CVE-2024-55591). Security Arsenal broadens the picture with Check Point and Cisco Secure Firewall, plus ConnectWise ScreenConnect (CVE-2024-1708). Added to that are stolen or purchased credentials, exposed RDP, phishing campaigns with macro-enabled documents, and abuse of remote administration services such as ScreenConnect or RMM-style tools.

Once inside, the operation aims for persistence and reconnaissance. Intel471 describes the playbook as entry through Internet-exposed services, network mapping, identification of domain admin accounts, disabling of security tools, and payload distribution through NETLOGON. DataEnforce, meanwhile, points to mass document reading or downloading from a single account, lateral access to repositories across multiple subsidiaries, anomalous VPN authentications, and sustained transfers to unknown cloud endpoints. That suggests a clear focus on the pre-encryption stage, when containment is still possible.

Defense disruption is another key trait. Cynet documented the use of PoisonX3.sys and PoisonX4.sys, installed as services under HKLM\SYSTEM\CurrentControlSet\Services\PoisonX, to manipulate processes, network, files, and memory in order to terminate security services. Cybersecurity News adds anticheatG13.sys, a kernel driver used to terminate almost 180 security-related processes. Security Arsenal mentions shadow copy deletion with vssadmin or wmic, disabling backups and antivirus, and behavior consistent with BYOVD. That set is not incidental, it is central to opening the path to encryption.

The ransomware itself is also well characterized. ManageEngine, DataEnforce, Infobae, Mallory.ai, and DEFOnline agree on the use of Go and Garble obfuscation. According to the sources, the encryptor has builds for Windows, Linux, BSD, NAS, ESXi, and virtualized environments, and in some cases requires a specific password to run. That limits uncontrolled spread and complicates sandbox analysis. RST Cloud and Mallory.ai add the use of XChaCha20 and Curve25519, while DEFOnline highlights aggressive self-propagation capabilities inside the compromised network.

Exfiltration usually precedes encryption by 48 to 72 hours, according to Security Arsenal, and total dwell time in the network ranges from 4 to 14 days before detonation. That window is especially important for detection and response, because the pre-encryption activity is where the most exploitable patterns appear, such as service enumeration, mass reads, lateral movement, and log wiping. The model is not built around an instant strike. It is built around progressively degrading defenses so that the extortion phase begins with as much control and as much stolen data as possible.

Operational chain of The GentlemenInitial accessVPN, Fortinet, RDPReconnaissanceNmap, admin, networkEvasionBYOVD, kill securityExfiltration48 to 72 hours beforeEncryption and pressureLeak site, ransom
Observed attack chain — From the perimeter to encryption, with prior exfiltration and defense evasion.
TTP Description Source
T1190 Exploitation of exposed applications, such as VPNs and firewalls Cyware, Security Arsenal, MITRE ATT&CK
Initial access via RDP Use of exposed remote services Security Arsenal, GalaxyWarden
Phishing with macros Initial delivery through malicious documents Security Arsenal, GalaxyWarden
Stolen or purchased credentials Access through valid accounts DataEnforce, Security Arsenal
Compromised RMM Abuse of ScreenConnect and similar tools Security Arsenal
Internal reconnaissance Nmap, Advanced IP Scanner, and network enumeration DataEnforce
Defense disruption BYOVD, PoisonX, anticheatG13.sys, GentleKiller Cynet, Cybersecurity News, Mallory.ai
Shadow copy deletion vssadmin, wmic Security Arsenal
Pre-encryption exfiltration Data theft before encryption DataEnforce, Security Arsenal, Mallory.ai
Encryption for impact Windows, Linux, BSD, NAS, ESXi ManageEngine, Ransomware.live, Halcyon

Regional impact

Regional overview

The regional footprint of The Gentlemen is broad and well documented in the material. This is not an actor focused on a single geography, but an operation that found fertile ground in multiple markets at once. Aggregated sources place it with victims in North America, South America, Europe, Africa, and Asia. Within that map, Latin America stands out as a particularly exposed zone, both because of specific victims and because of tactics that exploit surface areas common in the region, such as Fortinet FortiGate, exposed RDP, unpatched VPNs, and overly privileged administrative accounts.

The Latin American pattern is not uniform. In some cases, such as Ecopetrol, there is partial corporate confirmation and subsequent regulatory alerts. In others, such as Oldelval, the incident was operationally contained but remained a public claim by the group. In Peru, the Municipality of San Luis appears in several records as a leak-site listing, but without official breach confirmation. In Chile, Grupo Minero Las Cenizas was marked as an unconfirmed claim. In Brazil, Intranet Gov Brasil appears as a leak-site post still lacking confirmation from authorities. Mexico, meanwhile, was exposed through an intrusion against Advanced Marketing, also without all technical details released.

Colombia

Ecopetrol is the most relevant regional case and also the most difficult to verify fully. On July 17, 2026, the company detected irregular access that led to unauthorized downloads of data linked to roughly 3,300 user accounts and cloud environments belonging to 15 group companies. Available reporting agrees that there was no mass encryption or direct impact on production operations, but there was data exfiltration and a later public extortion attempt.

The Gentlemen claimed on its site to have exfiltrated more than 1 TB and 65 million documents. That figure, however, was not independently validated and should be treated as the actor’s claim. What matters from a regional defense perspective is that the case confirmed the combination of irregular access, extortion pressure, and information publication, and prompted official responses. ColCERT issued a high-risk alert for Colombia’s business sector on July 18, 2026, and reinforced recommendations for urgent patching of Fortinet FortiGate devices, other VPNs, and mandatory two-factor authentication.

The case also helped cement the public association between The Gentlemen and a perimeter-focused intrusion model. DataEnforce described the incident as an intrusion publicly attributed in reporting to the group and recalled that ColCERT had already linked The Gentlemen to more than 200 attacks in 50 countries by April 2026. In narrative terms, Ecopetrol became a trigger for greater regional visibility for an operation that was already expanding.

Colombia, Ecopetrol caseIrregular access3,300 accounts and 15 group companiesThreat actor claimMore than 1 TB, according to the leak sitePublic responseHigh alert and MFA, ColCERTOperational impactNo mass encryption
Colombia and Ecopetrol — LATAM's most visible case, with exfiltration and ColCERT response.

Argentina

Oldelval appears as the strongest Argentine case in the material. The company was listed by The Gentlemen on July 23, 2026, with a reference to the exfiltration of internal files during a ransomware attack. Public reports indicate that the company did not issue a detailed breach notice and that the number of affected individuals and the volume of compromised data remained unknown. Even so, the company’s communication to the National Securities Commission described an impact limited to administrative systems, while crude oil transport continued without interruption and the incident was declared fully contained.

On the technical side, DEFOnline describes the associated malware as developed in Go, obfuscated with Garble, and capable of aggressive self-propagation inside the network, with fast hybrid encryption based on Curve25519 and XChaCha20. The Rio Times and FalconFeeds added the context of a public claim by the group, but without official attribution confirmation. The analytical value of the case is that it shows a scenario where operational continuity is preserved, but the administrative surface is exposed and pressure from the leak site remains active.

Chile

Chile appears in the material as a geography with several claims, but little public confirmation. Security Chu mentioned alleged confirmed attacks against La Cámara Seguros, the INDH, and Corporación Colina, though without technical details or independent validation. The most concrete case is Grupo Minero Las Cenizas, listed by The Gentlemen on July 31, 2026, with an assertion of internal file exfiltration. GalaxyWarden specified that the entry did not detail the number of records or the types of information stolen and that the incident remained unconfirmed because the company had not issued a breach notification.

Chile’s value in this corpus is methodological. It shows how leak sites can include corporate or institutional names that then circulate through media and aggregators without official confirmation. For an intelligence team, that requires separating actor claims, media mentions, and validated facts immediately.

Peru

The Municipality of San Luis, in Lima, was listed by The Gentlemen on July 31, 2026. GalaxyWarden, Dexpose, Hookphish, Ransomware.live, RecentBreaches, and BreachSense agree that this was an actor claim with a threat to publish sensitive data, but without official breach confirmation from the municipality. Ransomware.live recorded 38 compromised users, though there is still no publicly verifiable detail on the scope of the leak.

What makes the case interesting is the convergence between what was reported in the media and what appeared in the group’s narrative. There was also an earlier post on X that mentioned a hack of the municipality’s computer systems on July 24, with temporary impact on online queries and payments and the activation of recovery protocols. That does not confirm attribution, but it does reinforce the idea that local service platforms are a frequent pressure point.

IntelFusions also said that between July 30 and 31, The Gentlemen posted new victims, including municipal governments in Brazil and Peru, amid a spike in activity. In regional terms, Peru therefore sits in an environment where the operation combines leak-site claims with low official visibility and possible exposure of municipal infrastructure.

Brazil

Brazil is another recurring focus in the material. The Intranet Gov Brasil case, listed on August 7, 2026, was presented by The Gentlemen as an intrusion into the internal network and digital portal used by the Brazilian federal government. GalaxyWarden and Ransomware.live clarified that, at the time of publication, there was no public confirmation from the government or from Serpro or Dataprev, and classified the case as an unconfirmed claim.

The value of this record lies in the combination of institutional sensitivity and lack of validation. It is a clear example of how a leak site can try to amplify the impact of a claim in government environments to force media attention, even when the available evidence is limited to the actor’s own announcement. IntelFusions also noted that during July 30 and 31 the group posted municipal governments in Brazil and Peru during a wider activity spike, suggesting the region was being pushed more aggressively at that point.

Mexico

Mexico appears through Advanced Marketing, a books distribution and publishing company with the domain advmkt.com.mx, listed by The Gentlemen on July 25, 2026. GalaxyWarden, Dexpose, and HackerFeeds agree that there was a direct claim by the group, with a threat to leak sensitive data if negotiations did not begin. Some aggregators classified the case as medium severity, but by late July no ransom amount, data volume, or detailed technical indicators had been published.

The relevance of the incident is tactical. GalaxyWarden notes that The Gentlemen often targets mid-sized companies in Latin America and Europe through phishing or exploited RDP services, followed by rapid exfiltration of sensitive files before encryption. That approach fits many mid-market Mexican organizations, where exposed perimeter services and remote access management remain high-yield entry points for ransomware operators.

United States

The United States appears in multiple sources as both a priority market and a source of specific victims. Mallory.ai identified Control Concepts Technology, based in Texas, as a ransomware victim attributed to The Gentlemen, and TopMark Funding, based in California, as another data breach linked to the group. It also reported Kenaitze Indian Tribe in Alaska as a victim dated July 31, 2026, along with other U.S. organizations such as Promatrix.

Security Arsenal said that within a batch of 25 new victims, Germany and the United States were the group’s primary markets, with entities ranging from 50 to 500 employees. BankInfoSecurity and S-RM also placed The Gentlemen among the prolific operations before it suffered its own internal leak. Although the focus of this investigation is Latin America, the United States serves as an operational reference for the actor’s maturity and scale.

Countries without enough verifiable coverage

No additional verifiable facts were identified in the research for Paraguay, Bolivia, or Uruguay, and Mexico did not provide a second case beyond Advanced Marketing.

Technical indicators

The Gentlemen has an unusually rich public technical footprint for a relatively young RaaS operation. Halcyon publishes locker hashes, the leak site URL, and behavioral patterns for the Go binary. Ransomware.live documents 42 IoCs associated with the operation. Cynet provided hashes for the PoisonX3.sys and PoisonX4.sys drivers. Gurucul and Hunt.io added affiliate infrastructure with domains, IPs, and EtherRAT components. Cyfar.ca expanded the set with hashes, IPs, and command-line fragments.

Type Value Source
SHA-256 hash 4948e89b532804590490aaae41f4b582a89592c931e557b6ddfff0b8d6ee8cf5 Cynet
SHA-256 hash 83DB6A37D9EC9923CA2AA677B4F4D8B67C8B2468046D21136A57FFE92EBA6CAC Cynet
Domain itemrange.com Gurucul
Domain wiselystarting.com Gurucul
Domain simultaneouslypower.com Gurucul
Domain resumeacceptable.com Gurucul
Domain publisherresolution.com Gurucul
IP 193.233.202[.]17 Hunt.io, CyberPress
IP 146.103.127[.]44 Gurucul
IP 77.110.126[.]46 Gurucul
IP 77.110.122[.]58 Gurucul
Hash anticheatG13.sys Cybersecurity News
File PoisonX3.sys Cynet
File PoisonX4.sys Cynet
Session ID Session associated with Ransomware.live Ransomware.live
Tox ID 3 published Tox identifiers Ransomware.live
IoCs and public footprint of The GentlemenDrivers: PoisonX3.sys, PoisonX4.sys, anticheatG13.sysDomains: itemrange.com, wiselystarting.com, simultaneouslypower.com, resumeacceptable.com, publisherresolution.comIPs: 193.233.202[.]17, 146.103.127[.]44, 77.110.126[.]46, 77.110.122[.]58Technical layer: Go, Garble, XChaCha20, Curve25519, PsExec, NETLOGON
Public technical footprint — Infrastructure and artifacts published by intelligence sources.

The absence of some complete values, such as the exact leak site URL in all sources or the full hashes of every published sample, does not reduce the utility of the set. For defense, there are already enough infrastructure and behavior indicators to strengthen detection rules in DNS, proxy, EDR, and exposed-service monitoring.

Analysis for security teams

The defensive priority against The Gentlemen is not the moment of encryption, but the hours and days before it. The material shows that the actor often remains in the network for 4 to 14 days before detonation and begins exfiltration 48 to 72 hours before encryption. That means any reconnaissance, lateral access, or mass-read behavior appearing on administrative accounts or unusual VPN connections should be treated as high-value signal.

The first mitigation block should focus on the access surface. The research is very clear about Fortinet FortiGate, FortiOS, FortiProxy, Citrix NetScaler ADC, and SonicWall SSL VPN. ConnectWise ScreenConnect, compromised RMM tools, and exposed RDP also appear. In practical terms, that means patching with high priority, reviewing public exposure of remote consoles, cutting unnecessary access, and checking multifactor authentication on every entry point. The Colombian case shows that edge-appliance exploitation remains a high-return door for the actor.

The second block is behavioral detection. DataEnforce lists highly actionable signals, such as mass reading or downloading by a single account, access to repositories across multiple subsidiaries, anomalous VPN authentications, Advanced IP Scanner or Nmap execution from administrative contexts, sustained outbound transfers to unknown cloud endpoints, and attempts to disable endpoint protection or delete logs. Add to that vssadmin, wmic, PsExec, WMI, NETLOGON, strange service creation, unusual or unsigned kernel drivers, and any BYOVD pattern. If the organization has well-tuned EDR telemetry, The Gentlemen leaves a fairly recognizable sequence before encryption.

The third block is impact containment. The use of a Go payload with a specific password suggests an operator trying to avoid uncontrolled spread, while still pointing to deliberate deployment across multiple hosts. Privileged access should be segmented, cross-repository read access reduced, excessive cloud permissions reviewed, and backup access hardened. Security Arsenal and Cynet show that shadow copy deletion and security-tool tampering are part of the chain, so backup protection must be treated as a primary attacker target, not an auxiliary asset.

The fourth block is active hunting for affiliate infrastructure. Gurucul, Hunt.io, and CyberPress show that The Gentlemen does not operate only with the encryptor, but with staging, reverse shell, C2, and exfiltration tools supported by specific domains and IPs. The EtherRAT case, moreover, introduces a C2 component via Ethereum smart contracts, which complicates purely perimeter-based blocking. For SOC teams, that means DNS, proxy, and egress telemetry matter just as much as endpoint data.

The tactical priority, then, is this order, patch edge surfaces, enforce MFA on remote access, monitor exfiltration and administrative behavior, harden privileges, protect backups, and hunt for abnormal drivers or services. In Latin America, where many of the actor’s intrusions rely on exposed perimeters and reused credentials, that order is more useful than any generic ransomware rule.

Limitations of the material

The available corpus allows for a fairly detailed reconstruction of the operation, victimology, and several TTPs, but it does not support a definitive technical attribution beyond the designations cited by each vendor. Some sources present victim claims that were not confirmed by the affected organizations or by authorities. That applies in particular to leak-site entries on Intranet Gov Brasil, Grupo Minero Las Cenizas, Mercado Libre, and certain Chile cases.

There are also discrepancies in victim counts. Some sources speak of 135, 144, 269, 300, 320, 340, 456, 483, or 580 organizations, depending on the time cut and methodology. Those numbers reflect leak-site claims, vendor estimates, or third-party datasets, not a single verifiable total of confirmed incidents. For that reason, this report kept the distinction between confirmed facts and unconfirmed claims or attributions.

It was not possible, from the material provided, to independently verify the full technical detail of some Latin American intrusions, such as exact data volumes, number of affected people, compromised credentials, or definitive initial vectors in each case. In Ecopetrol and Oldelval, for example, there are solid descriptions of impact and the actor’s narrative, but not all claimed figures were publicly validated.

There is also not enough verifiable material to develop specific blocks for Paraguay, Bolivia, or Uruguay, or to build a single technical attribution about the group’s human leadership beyond what each source attributes or suggests. The report therefore limits itself to consolidating facts cited by the research and keeping uncertainty explicit where appropriate.

Sources

View all