A Russian-speaking ransomware-as-a-service operation that went from closed crew to the second-most prolific gang on record in months — then got breached itself, exposing that ~78% of victims paid quietly. Attribution, TTPs, encryptor internals, IOCs and a defender playbook. Every claim is sourced.
The Gentlemen is a Russian-speaking RaaS operation that emerged mid-2025 and
went RaaS in September 2025. It is run by the actor hastalamuerte (aka zeta88),
tracked as LARVA-368 (PRODAFT) and Storm-2697 (Microsoft) — a former Qilin affiliate
who split after a July 2025 payment dispute (~$48K unpaid commission, aired publicly on the RAMP forum).
| Attribute | Detail |
|---|---|
| Primary alias | hastalamuerte / zeta88 |
| Cluster tracking | LARVA-368 (PRODAFT Phantom Mantis) · Storm-2697 (Microsoft) |
| Origin | Russian-speaking; ran affiliate crew "ArmCorp" inside Qilin RaaS |
| Split catalyst | 22 Jul 2025 RAMP arbitration vs Qilin — ~$48,000 unpaid commission |
| Emergence | Closed crew mid-2025 → RaaS Sept 2025; recruits via BreachForums |
| OPSEC irony | The operation itself was hacked and leaked; internal chats exposed |
Notable: Group-IB found the operator uploaded an independent locker 5 days before the public Qilin arbitration — i.e. was building The Gentlemen while still a Qilin affiliate. A premeditated exit, not a reactive one.
| Stage | Observed |
|---|---|
| Initial access | Internet-facing services / stolen creds — exposed firewall & VPN management (FortiGate) 🎯 |
| Discovery | 1.bat enumerating 60+ domain accounts; Advanced IP Scanner, Nmap, AD + virtualization-group queries (VMware) |
| Priv-esc | PowerRun.exe — UAC bypass, run as SYSTEM |
| Defense evasion | BYOVD: ThrottleBlood.sys (abuses signed ThrottleStop driver) for kernel-level kill of security tools; PowerShell blinds Defender, re-enables SMB1, loosens LSA — then drops the payload |
| Lateral / persist | PsExec, AnyDesk; GPO abuse to push payloads domain-wide; self-propagating encryptor |
| C2 | SystemBC (SOCKS5, RC4), Cobalt Strike, AnyDesk |
| Impact | Data theft before encryption → double extortion; ESXi variant kills VMs, inhibits recovery |
Signature strength = tailored defense evasion — they iteratively fingerprint the victim's specific security stack and swap tooling when blocked.
--spread <domain/user:password>, falls back to the current session token.--password (analyzed sample: 9VoAvR7G).--full (→ --system + --shares), --fast/--superfast/--ultrafast (coverage vs speed), --wipe, --keep, --silent.gentlemen_system; env var LOCKER_BACKGROUND=1; branded PowerShell console banner.| Type | Value | Note |
|---|---|---|
| MD5 | adf675ffc1acb357f2d9f1a94e016f52 | Gentlemen sample |
| MD5 | de1a114a2c5552387a1bbb61501bf129 | Gentlemen sample |
| Filename | 1.bat | mass account enum (60+) |
| Loader | All.exe | defense-evasion loader |
| Driver | ThrottleBlood.sys | BYOVD (ThrottleStop abuse) |
| Tool | PowerRun.exe | UAC bypass / priv-esc |
| Sched task | gentlemen_system | SYSTEM re-exec |
| Env var | LOCKER_BACKGROUND=1 | background worker flag |
| C2 / proxy | SystemBC, Cobalt Strike | SOCKS5 / RC4 |
Full structured IOC sets, ATT&CK mappings and Sigma rules: Microsoft Defender IOCs + hunting queries, SOC Prime Sigma rules, Trend Micro appendix.
ThrottleStop/ThrottleBlood.sys).Primary / authoritative, all publicly published: Microsoft Security Blog (Go-encryptor deep-dive), Trend Micro ("Unmasking The Gentlemen"), Check Point Research / The Hacker News (SystemBC C2, 1,570+ networks, ESXi variant), Group-IB (attribution), Halcyon / Analyst1 (Qilin split, RAMP arbitration), FortiGuard, SOC Prime (detection rules). Supporting: SOCRadar, Cybereason, S-RM, CSO Online, Dark Reading, TechNadu, Cyberpress, Huntress.
We map your external perimeter the way an attacker does — passive, evidence-first, closed-loop remediation. The first finding is free.