The Gentlemen & SystemBC: A Sneak Peek Behind the Proxy

April 20, 2026, 4:54 p.m.

Description

The Gentlemen ransomware-as-a-service program has rapidly expanded since mid-2025, claiming over 320 victims with 240 attacks occurring in early 2026. The service provides multi-platform lockers for Windows, Linux, NAS, BSD, and ESXi, enabling comprehensive coverage of corporate environments. During an incident response engagement, an affiliate deployed SystemBC proxy malware for covert tunneling and payload delivery. Analysis of the SystemBC command-and-control server revealed a botnet of over 1,570 victims, primarily corporate and organizational targets. The intrusion progressed from domain controller compromise through credential validation, remote execution via administrative shares, and deployment of Cobalt Strike payloads. Attackers disabled defenses, established persistence through scheduled tasks and services, and ultimately deployed ransomware via Group Policy. The operation demonstrates sophisticated lateral movement capabilities, defense evasion techniques, and integration of mature post-exploit...

Date

  • Created: April 20, 2026, 3 p.m.
  • Published: April 20, 2026, 3 p.m.
  • Modified: April 20, 2026, 4:54 p.m.

Indicators

  • 994d6d1edb57f945f4284cc0163ec998861c7496d85f6d45c08657c9727186e3
  • b67958afc982cafbe1c3f114b444d7f4c91a88a3e7a86f89ab8795ac2110d1e6
  • 5dc607c8990841139768884b1b43e1403496d5a458788a1937be139594f01dca
  • 8c87134c1b45e990e9568f0a3899b0076f94be16d3c40fa824ac1e6c6ee892db
  • c46b5a18ab3fb5fd1c5c8288a41c75bf0170c10b5e829af89370a12c86dd10f8
  • c7f7b5a6e7d93221344e6368c7ab4abf93e162f7567e1a7bcb8786cb8a183a73
  • 788ba200f776a188c248d6c2029f00b5d34be45d4444f7cb89ffe838c39b8b19
  • 87d25d0e5880b3b5cd30106853cbfc6ef1ad38966b30d9bd5b99df46098e546c
  • 025fc0976c548fb5a880c83ea3eb21a5f23c5d53c4e51e862bb893c11adf712a
  • 9f61ff4deb8afced8b1ecdc8787a134c63bde632b18293fbfc94a91749e3e454
  • a7a19cab7aab606f833fa8225bc94ec9570a6666660b02cc41a63fe39ea8b0ad
  • 91415e0b9fe4e7cbe43ec0558a7adf89423de30d22b00b985c2e4b97e75076b1
  • 860a6177b055a2f5aa61470d17ec3c69da24f1cdf0a782237055cba431158923
  • fe1033335a045c696c900d435119d210361966e2fb5cd1ba3382608cfa2c8e68
  • 22b38dad7da097ea03aa28d0614164cd25fafeb1383dbc15047e34c8050f6f67
  • ec368ae0b4369b6ef0da244774995c819c63cffb7fd2132379963b9c1640ccd2
  • 2ed9494e9b7b68415b4eb151c922c82c0191294d0aa443dd2cb5133e6bfe3d5d
  • 1eece1e1ba4b96e6c784729f0608ad2939cfb67bc4236dfababbe1d09268960c
  • 3ab9575225e00a83a4ac2b534da5a710bdcf6eb72884944c437b5fbe5c5c9235
  • efaf8e7422ffd09c7f03f1a5b4e5c2cc32b05334c18d1ccb9673667f8f43108f
  • 992c951f4af57ca7cd8396f5ed69c2199fd6fd4ae5e93726da3e198e78bec0a5
  • 62c2c24937d67fdeb43f2c9690ab10e8bb90713af46945048db9a94a465ffcb8
  • 48d9b2ce4fcd6854a3164ce395d7140014e0b58b77680623f3e4ca22d3a6e7fd
  • cc14df781475ef0f3f2c441d03a622ea67cd86967526f8758ead6f45174db78e
  • f736be55193c77af346dbe905e25f6a1dee3ec1aedca8989ad2088e4f6576b12
  • fc75ed2159e0c8274076e46a37671cfb8d677af9f586224da1713df89490a958
  • http://tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion/

Additional Informations

  • tezwsse5czllksjb7cwp65rvnk4oobmzti2znn42i43bjdfd2prqqkad.onion
  • United Kingdom of Great Britain and Northern Ireland
  • Germany
  • United States of America