Ransomware affiliate leak exposes The Gentlemen’s playbook

March 21, 20262 min read2 sources
Share:
Ransomware affiliate leak exposes The Gentlemen’s playbook

A ransomware affiliate using the name “Hastalamuerte” has reportedly leaked operational details tied to The Gentlemen ransomware-as-a-service group, offering a rare look at how the crew gains access, evades defenses and structures attacks. According to Infosecurity Magazine, the exposed material references FortiGate exploitation, bring-your-own-vulnerable-driver (BYOVD) techniques and “split tactics” linked to Qilin-style operations.

The reported FortiGate angle matters because edge devices remain a common entry point for ransomware crews. Compromising a firewall or remote access appliance can give attackers a foothold before they move laterally inside a victim network. The leak did not publicly tie the activity to a specific Fortinet CVE, but FortiGate flaws and stolen credentials have repeatedly featured in real-world intrusion chains. Organizations running internet-facing firewalls and VPN infrastructure should review patch status, exposed management interfaces and authentication logs.

The mention of BYOVD suggests The Gentlemen or its affiliates are using signed but vulnerable drivers to disable or bypass endpoint protections before deploying ransomware. That technique has become a favored way to tamper with EDR and antivirus tools without using obviously malicious kernel code. In practice, it gives attackers a better chance of reaching encryption and extortion stages undetected.

The reference to Qilin “split tactics” points to another trend: ransomware brands increasingly operate as loose affiliate networks, with intrusion, data theft and encryption sometimes handled by different actors or separate infrastructure. That makes attribution harder and disruption less durable, since operators can rebrand or shift tooling quickly when exposed.

There is no public victim list attached to this leak so far. Still, the disclosure is useful intelligence for defenders because affiliate leaks often reveal the real mechanics behind ransomware campaigns more clearly than victim posts or leak-site claims. Security teams should treat the report as a reminder to harden perimeter devices, monitor for unusual driver loads and look for signs of endpoint tampering before encryption begins.

Share:

// SOURCES

// RELATED

Meta settles bellwether lawsuit alleging addictive design harmed student mental health

Meta's confidential settlement with a Washington school district marks a pivotal moment in the massive litigation against social media's psychological

6 min readMay 24

Huawei zero-day attack behind last year’s crash of Luxembourg's entire telecoms network

A sophisticated zero-day attack on Huawei routers allegedly caused Luxembourg's 2023 national telecom outage, raising severe global security concerns.

6 min readMay 23

MiniPlasma Windows 0-day enables SYSTEM privilege escalation on fully patched systems

A newly disclosed 0-day flaw, MiniPlasma, allows attackers to gain full SYSTEM control on patched Windows systems, with a public PoC accelerating risk

6 min readMay 18

The ransomware dilemma: why more than half of security chiefs would pay the price

A new survey reveals 56% of CISOs would consider paying a ransom, highlighting the intense pressure to restore operations despite official guidance.

6 min readMay 16