When a ransomware gang gets ransomware'd: what The Gentlemen's leak reveals about the RaaS economy- 232
May 10, 2026
In early May 2026, one of the most prolific ransomware-as-a-service operations running today discovered what its own victims have felt for the better part of a year: total exposure. The Gentlemen, a group that published roughly 330 victims to its leak site within the first half of 2026 alone, suffered a breach of its own backend — chat logs, affiliate rosters, negotiation transcripts, tooling discussions, and server credentials all spilled into public view — offering rare, unfiltered visibility into how a modern criminal enterprise actually runs itself day to day.
The Gentlemen's origin story is itself a case study in the fluid, faction-riven nature of today's ransomware ecosystem. The group's administrator, a Russian-speaking operator known as hastalamuerte or zeta88, previously ran an affiliate crew called ArmCorp under the established Qilin ransomware program. In July 2025, he went public on the RAMP underground forum accusing Qilin's operators of withholding roughly $48,000 in commission — a dispute that served as the public trigger for his departure. But the timeline tells a different story: the earliest known Gentlemen ransomware sample had already been uploaded to VirusTotal five days before that arbitration post went live, meaning hastalamuerte was quietly building an independent, multi-platform operation, complete with custom infrastructure and its own data leak site, while still formally affiliated with the group he was about to abandon. What followed was rapid scaling built on a specific commercial insight: The Gentlemen offer affiliates a 90/10 revenue split, unusually generous by RaaS standards, which proved effective at pulling experienced operators away from competing programs.
The technical architecture reflects a deliberately cross-platform, double-extortion operation — a Go-based locker capable of hitting Windows, Linux, NAS, and BSD systems, paired with a dedicated C-based variant built specifically for ESXi hypervisors, encrypting data while threatening publication if ransoms go unpaid. What stands out geopolitically is the targeting logic: only about 13 percent of victims are based in the United States, with concentrations instead in Thailand, the UK, Brazil, Germany, and India, while the group's own internal rules explicitly prohibit targeting Russia or other CIS states — the now-familiar signature of Russian-speaking criminal infrastructure operating under an implicit non-aggression pact with its home region. The leaked chats reveal an even more specific pattern beneath that footprint: initial access operations concentrate heavily in APAC, while high-value monetization is then selectively pursued in the UK, US, and Western Europe — suggesting APAC compromises function either as stepping stones into Western supply chains or as lower-value access resold to other actors entirely.

The operational detail exposed by the leak reads less like an underground crew and more like a functioning mid-size company. zeta88 runs the affiliate program the way a department head would, assigning targets internally referred to as "cases," distributing tooling packages, setting revenue terms, purchasing hardware for under-resourced affiliates, and removing non-performers. The group cross-references prospective victims against ZoomInfo revenue data to calibrate ransom demands — in one documented case, setting a demand to match a victim's known $10 million cyber insurance ceiling with precision rather than guesswork. Tradecraft is institutionalized rather than left to individual initiative: one operator, Wick, publishes internal multi-step guides on techniques like Velociraptor deployment and browser session theft, the Conti pentester guide circulates as a training resource, and the group has a stated preference for commercially signed and open-source tools — signed Velociraptor builds, TailVNC, Rclone, OpenConnect — specifically because signed binaries evade common antivirus and EDR detection. Insider-threat awareness runs through the operation's own security culture: sensitive credentials move over Tox rather than the group's regular Rocket.Chat instance, source code and locker binaries are withheld from most affiliates, and the group maintains the ability to rotate its Tor address without losing its backend database.

None of this operational sophistication guarantees the group's demise. As this publication has noted with prior leaks, exposure alone rarely ends a ransomware operation — Conti survived its own leak for months, and Black Basta simply reshuffled and continued. zeta88's own response to this breach was reportedly dismissive, accompanied by a list of planned upgrades rather than any sign of retreat. What the leak actually offers is not an ending but an unusually precise blueprint: documented proof that unpatched FortiGate appliances, MFA deployed without credential-abuse monitoring, and weak Active Directory hardening are being exploited systematically by a well-organized, revenue-optimizing operation — intelligence whose value depends entirely on whether defenders act on it before the next victim appears on a leak site.