216.73.217.22

LBIOC-20260071 - The Gentlemens Leak

· Published 13/05/2026 11:08 · Modified 13/05/2026 10:03

Export JSON

Essential information

Published
13/05/2026 11:08
Modified
13/05/2026 10:03
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
affiliate data-leak extortion hastalamuerte killav linux powerrun qilin ransomware systembc the gentlemen windows
Tags
2026-05-13 affiliate data leak extortion hastalamuerte killav linux powerrun qilin ransomware systembc the gentlemen windows
Related entities
26 indicators, 26 observables, 1 intrusion sets (apt), 20 techniques (mitre), 4 malware

Description

is an active and operation that emerged publicly in the second half of 2025, rapidly escalating into a high-volume threat actor. The group appears to be a continuation or reorganization of prior activity, with reported connections to the ecosystem and the Russian-speaking actor '.' This growth likely reflects existing experience, relationships, and access to established resources. Underground sources indicate attempts to sell data allegedly connected to activity, though the available information lacks sufficient victim-specific or technical details to confirm authenticity. The operation utilizes for command and control communications and deploys variants targeting both and systems.

External references