Leaked backend gives insight into the ransomware group The Gentlemen

Researchers at Check Point have published an in-depth look at The Gentlemen, a ransomware-as-a-service operation whose internal backend systems were recently leaked online. The exposed data included internal chats, affiliate discussions, ransom negotiations, attack methods and operational details tied to the group's infrastructure.

According to the research, the group relied heavily on compromised credentials, edge-device vulnerabilities and NTLM relay attacks to gain initial access. The leak also suggested that administrators were directly involved in some attacks rather than only managing affiliates.

What this means for your organisation

What stands out is how unexotic the entry points are. Stolen passwords, unpatched internet-facing equipment and legacy Windows authentication are not advanced techniques, but they still work because cleaning them up is tedious. That gives a clear priority: the three things that close the door are the same three things that always sit at the bottom of the list.

Berigo recommends

  • Disable NTLM where possible, and map what still depends on it before you do.
  • Require multi-factor authentication on all remote access without exception, including administrators and suppliers.
  • Set the shortest practical patching deadline for internet-facing equipment.
  • Monitor for sign-ins using credentials known to have leaked, and force password changes.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch