Gentlemen RaaS Adds C-Based ESXi Locker To Cross-Platform Attacks

The Gentlemen ransomware-as-a-service (RaaS) operation is escalating its enterprise attacks by adding a highly specialized, C-based VMware ESXi locker to its diverse malware arsenal.

According to recent incident response data, affiliates of this rapidly growing group are also leveraging the SystemBC proxy malware to manage a massive botnet of over 1,570 compromised corporate environments.

ESXi Locker and Encryption Tactics

While The Gentlemen RaaS initially gained traction in mid-2025 using Go-based encryptors for Windows, Linux, BSD, and NAS systems, the group has recently introduced a purpose-built C-based payload specifically for ESXi servers.

This hypervisor-focused variant is engineered for speed and reliability, deliberately shutting down virtual machines to release file locks before encryption begins.

The locker first attempts a graceful power-off using ESXi command-line tools, escalating to forceful termination if virtual machines remain active.

To maximize encryption throughput, the malware alters the host’s storage layer by increasing the VMFS write buffer capacity and reducing flush intervals to force faster disk commits.

The ransomware also strategically creates and deletes eagerly zeroed thick disks to synchronize writes across datastores. During the encryption phase, the payload uses a hybrid cryptographic scheme combining XChaCha20 for file encryption and X25519 for key derivation.

The Gentlemen RaaS X/Twitter account (Source: checkpoint)
The Gentlemen RaaS X/Twitter account (Source: checkpoint)

The operators have programmed the ESXi locker to exclude critical boot and system directories, ensuring the underlying host remains operational enough to display the ransom note.

The ransomware offers operators optional speed configurations that allow them to encrypt only a fraction of large files. Affiliates can choose to lock 9 percent in “fast” mode, 3 percent in “superfast” mode, or 1 percent in “ultrafast” mode.

This intermittent encryption drastically reduces the time required to lock massive virtual disk files while still rendering the data completely unrecoverable without the attacker’s unique decryption key.

SystemBC global accesses (Source: checkpoint)
SystemBC global accesses (Source: checkpoint)

Proxy Botnets and Mass Deployment

Beyond the encryptor itself, the infrastructure supporting The Gentlemen attacks has matured significantly. Security researchers recently discovered an affiliate utilizing SystemBC, a proxy malware, to establish covert SOCKS5 network tunnels within victim environments.

Top 15 Infected countries (Source: checkpoint)
Top 15 Infected countries (Source: checkpoint)

The associated command-and-control server revealed a global botnet of over 1,570 infected hosts, primarily located in the United States, the United Kingdom, and Germany.

This extensive footprint indicates that affiliates are integrating The Gentlemen payloads into sophisticated, human-operated intrusion workflows rather than conducting opportunistic attacks.

To facilitate lateral movement before the checkpoint final encryption, the ransomware includes a built-in spreading mechanism.

If the operator supplies harvested domain credentials, the malware automatically enumerates reachable hosts. It pushes the payload through parallel execution channels, including WMI, PsExec, scheduled tasks, and remote services.

Furthermore, the ransomware targets and terminates a wide range of enterprise backup and recovery services, including Veeam and Windows Shadow Copies, to eliminate any chance of data recovery.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories