Ransomware Group Targets Fortinet and Cisco Devices To Breach Networks

The Gentlemen ransomware-as-a-service operation has rapidly evolved into one of the most prolific cyber threats of 2026.

Emerging in mid-2025, this cybercriminal syndicate has surged to become the second-most-active ransomware group globally, with over 330 victims published on its dark web leak site in the first five months of 2026 alone.

Recent intelligence reveals that the actual infection scale is vastly larger. Researchers uncovered a command-and-control server exposing over 1,570 compromised corporate environments.

This exponential growth is fueled by an aggressive profit-sharing model that heavily favors affiliates, luring experienced threat actors away from competing ransomware cartels by offering them90% of the ransom.

The group employs double-extortion tactics, demanding ransom payments while threatening to publish sensitive stolen data online.

They actively target small- to medium-sized organizations across more than 50 countries, with a significant operational focus on Asia, the United States, and Europe, impacting critical sectors such as healthcare, energy, and manufacturing.

Recently, the tables turned on The Gentlemen when an internal database was leaked on an underground forum.

The leaked communications exposed the group’s highly organized operational workflow, infrastructure details, and the extensive toolsets utilized by their affiliates to infiltrate corporate networks and orchestrate wide-scale encryption.

Ransomware Targets Edge Devices

The leaked internal chats detail a systematic approach to breaching target networks, primarily focusing on exploiting exposed edge devices.

Affiliates frequently target Fortinet FortiGate virtual private network appliances and Cisco platforms.

Zeta88 advertising The Gentlemen’s RaaS (Source: checkpoint)
Zeta88 advertising The Gentlemen’s RaaS (Source: checkpoint)

The group maintains an alarming inventory of approximately 14,700 compromised FortiGate devices exploited via known vulnerabilities, alongside hundreds of validated brute-forced credentials.

They achieve initial access through credential brute-forcing, exploiting known public-facing vulnerabilities, or purchasing access from specialized third-party initial access brokers.

RaaS admin in underground forum (Source: checkpoint)
RaaS admin in underground forum (Source: checkpoint)

Screenshots shared in the chats also show them searching for accounts and credentials on data breach search engines.

Once they obtain a foothold, they treat these systems as pivots to move deeper into the internal network.

According to Checkpoint research, the Gentlemen affiliates leverage a mature and sophisticated arsenal of tools for remote access, offensive operations, and defense evasion.

Onion page TOX ID (Source: checkpoint)
Onion page TOX ID (Source: checkpoint)

They heavily rely on NetExec for Active Directory discovery, SystemBC and Velociraptor for covert remote access, and customized tools like DumpBrowserSecrets to hijack corporate web sessions.

To exfiltrate large volumes of data before deploying their custom multi-OS ransomware lockers, they use automated utilities via secure file transfer protocols, often staging data in hidden directories.

The leaked communications also highlight the group’s intent to abuse legitimate code-signing certificates to make their malicious binaries appear benign, taking inspiration from other notorious ransomware cartels like Black Basta.

Indicators of Compromise

Indicator TypeValue
Admin TOX ID (Zeta88)F8E24C7F5B12CD69C44C73F438F65E9BF560ADF35EBBDF92CF9A9B84079F8F04060FF98D098E
Affiliate TOX IDD2CBA43A1AF6D965432AE11487726DB84D2945CF2CD975D7774B76B54AF052418AC2E59ADA69
Affiliate TOX ID98C132E2B20B531BE6604397D97040C1E9EB42FCE12EDF119BCE8B4031CA5C70DAF5E65FA3C3

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories