The Gentlemen
Essential information
- Confidence
- 100/100
- Published
- 21/12/2025 16:02
- Modified
- 27/05/2026 15:52
- Updated at
- 27/05/2026 15:52
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 8 reports, 90 attack patterns (mitre), 15 malware, 8 sectors, 5 countries, 48 indicators, 6 vulnerabilities (cve)
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (8)
-
AlienVault Confidence 100 1 CVE 20 MITREs 4 Malwares 3 IOCs 3 Observables 1 APT
-
AlienVault Confidence 100 1 CVE 20 MITREs 3 Malwares 3 IOCs 3 Observables 1 APT
-
3 CVEs 20 MITREs 2 Malwares 33 Observables 1 APT
-
AlienVault Confidence 100 20 MITREs 4 Malwares 26 IOCs 26 Observables 1 APT
-
46 MITREs 6 Malwares 27 Observables 1 APT
-
AlienVault Confidence 100 4 CVEs 11 MITREs 7 Malwares 4 IOCs 4 Observables 1 APT
-
17 MITREs 1 Malware 1 APT
-
13 MITREs 1 APT
Attack patterns (MITRE) (90)
-
T1219 usesRemote Access Tools MITRE
-
T1573.002 usesAsymmetric Cryptography MITRE
-
T1036.005 usesMatch Legitimate Resource Name or Location MITRE
-
T1071 usesApplication Layer Protocol MITRE
-
T1021.004 usesSSH MITRE
-
T1106 usesNative API MITRE
-
T1550 usesUse Alternate Authentication Material MITRE
-
T1071.001 usesWeb Protocols MITRE
-
T1543.003 usesWindows Service MITRE
-
T1060 uses
-
T1190 usesExploit Public-Facing Application MITRE
-
T1133 usesExternal Remote Services MITRE
Malware (15)
-
Mimikatz usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
PowerRun usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
AnyDesk usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Medusa usesThe MITRE Corporation Confidence 100
[MEDUSA](https://attack.mitre.org/software/S1220) is an open-source rootkit that is capable of dynamic linker hijacking, command execution, and logging credentials.(Citation: Google Cloud Mandiant UNC3886 2024)
First seen 01/01/1970 · Last seen 16/11/5138 · -
SystemBC usesAlienVault Confidence 100
[SystemBC](https://attack.mitre.org/software/S9001) is a malware family offered as a malware-as-a-service (MaaS) that is used to establish command and control and facilitate follow-on activity, including ransomware deployment.[SystemBC](https://attack.mitre.org/software/S9001) executes a variety…
First seen 01/01/1970 · Last seen 16/11/5138 · -
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Babyk usesFamily
-
LockBit 5.0 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Babuk - S0638 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
KillAV usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Qilin usesFamily
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Sectors (8)
-
Government targets
-
Manufacturing targets
-
Healthcare targets
-
Construction targets
-
Insurance services targets
-
Transportation targets
-
Finance targets
-
Technology targets
Countries (5)
-
Thailand targets
-
United Kingdom of Great Britain and Northern Ireland targets
-
United States of America targets
-
Germany targets
-
Brazil targets
Indicators (48)
-
stix 100/100· Valid until 16/04/2027 · Source: AlienVault
-
stix 100/100· Valid until 16/04/2027 · Source: AlienVault
-
stix 100/100· Valid until 16/04/2027 · Source: AlienVault
-
stix 100/100· Valid until 16/04/2027 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 19/05/2026 · Source: AlienVault
-
stix 100/100· Valid until 10/05/2027 · Source: AlienVault
-
stix 100/100· Valid until 16/04/2027 · Source: AlienVault
-
stix 100/100· Valid until 16/04/2027 · Source: AlienVault
-
stix 100/100· Valid until 16/04/2027 · Source: AlienVault
-
stix 100/100· Valid until 16/04/2027 · Source: AlienVault
-
stix 100/100· Valid until 15/11/2026 · Source: AlienVault
-
stix 100/100· Valid until 10/05/2027 · Source: AlienVault
Vulnerabilities (CVE) (6)
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through …
- Attack vector
- Network
- Published
- 14/01/2025
- Modified
- 27/05/2026
Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially …
- Attack vector
- Network
- Published
- 20/10/2025
- Modified
- 27/05/2026
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may …
- Attack vector
- Network
- Published
- 09/06/2025
- Modified
- 27/05/2026
Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within …
- Attack vector
- Network
- Published
- 22/08/2023
- Modified
- 27/05/2026
Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) …
- Attack vector
- Local
- Published
- 29/09/2025
- Modified
- 27/05/2026
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an …
- Attack vector
- Network
- Published
- 30/07/2024
- Modified
- 27/05/2026