CiberLATAMbywhalemate

Argentina: The Gentlemen hit critical sectors

Kaspersky attributed attacks on manufacturing, health, tech, finance, construction and logistics to The Gentlemen, with activity confirmed in Argentina.

Whalemate Labs · AI-assisted researchPublished:Updated 3 min read

Kaspersky attributed attacks on manufacturing, health, technology, finance, construction and logistics to The Gentlemen, with activity confirmed in Argentina. In the Oldelval case, a later legal review said the duty to report to the CNV arose from securities law frameworks, not from a specific cybersecurity rule.

Update August 25, 2026: a legal review of the Oldelval disclosure clarified that the obligation to report the case to the CNV came mainly from securities law frameworks, not from a specific cybersecurity rule. That reading reinforces the role of financial regulators in transparency around cyber incidents affecting critical companies.

Kaspersky reported the global expansion of the ransomware group The Gentlemen against manufacturing, IT services and technology, health care, financial services, construction, and logistics companies. The group has operated under a RaaS model since mid-2025 and, according to the cited report, uses a Go-based backdoor and a Windows encryption variant. In parallel, available material places confirmed activity in Argentina attributed by threat intelligence sources to that actor, with a focus on victims such as Oldelval and on key industrial sectors in South America.

What changed in the Oldelval case?

A later legal review said the incident disclosure before the CNV was driven mainly by securities law frameworks and not by a specific cybersecurity obligation. That interpretation highlights how financial regulators end up shaping transparency around incidents that hit critical companies, even when notification does not stem from a dedicated cyber law.

What techniques did The Gentlemen use?

A threat hunting case study on The Gentlemen documented an attack chain that began with initial access through Internet-exposed firewall interfaces. The attackers then conducted network reconnaissance with Advanced IP Scanner, used PowerRun.exe for privilege escalation, and the ThrottleBlood.sys driver to evade defenses.

SOC Prime linked that attack chain to the abuse of exposed perimeter devices and recommended hardening services such as VPNs and FortiGate interfaces through strong authentication and rapid patching. The technical analysis points to a pattern that combines exposed remote access, internal movement, and mechanisms designed to make detection harder.

SecurityArsenal described cross-sector campaigns with multiple victims over a few days and recommended quickly isolating affected hosts, disabling compromised accounts with broad credential resets, and blocking exfiltration at the perimeter toward file-sharing and cloud storage domains. The material brings together a picture of sustained expansion, with impact on industrial and financial sectors and TTPs already linked to VPN, firewall, and remote access abuse in regional campaigns.

Sources

View all