Beware of The Gentlemen: The Fast‑Rising, Highly Aggressive Ransomware Syndicate
A ransomware collective calling itself The Gentlemen has rapidly climbed to the number‑two spot among the world’s most active extortion groups, driven by an unusually generous affiliate model that promises operators 90 percent of every ransom payment. That lucrative split has turned the group into a magnet for skilled hackers — and has also helped investigators trace clues about the real identity of the person running the operation.
A Ransomware‑as‑a‑Service Operation Built for Speed
Researchers at Check Point Software have been tracking The Gentlemen closely, describing it as a classic ransomware‑as‑a‑service (RaaS) program: the core developers build the malware and infrastructure, while affiliates carry out intrusions and share profits.
Check Point notes that the group’s 90/10 revenue model is far more aggressive than the typical 80/20 split used by competing RaaS programs. That difference, they say, has fueled a surge in recruitment and activity.
By Check Point’s count, The Gentlemen has claimed at least 332 victims since emerging in mid‑2025 — with more than 240 attacks in 2026 alone — making it the second most prolific ransomware group by victim volume this year.
Once inside a network, the attackers typically exploit Internet‑exposed systems such as VPN appliances and firewalls, then move rapidly to encrypt entire environments, often within hours.
The Administrator Behind the Curtain: Zeta88 / Hastalamuerte
Check Point’s analysis points to a single individual acting as the group’s architect and administrator. On Russian‑language cybercrime forums, this person uses the handle Zeta88, but earlier went by Hastalamuerte.
A breach of the group’s internal systems revealed that this same individual:
- Builds the ransomware locker
- Maintains the RaaS control panel
- Manages affiliate payments
- Collects the 10 percent cut from every ransom
This makes them the central operator of the entire enterprise.
Tracing the Digital Footprints
Cyber‑intelligence firm Intel 471 has compiled a detailed history of the user known as Hastalamuerte, who appears to be fluent in both Russian and English and has maintained accounts on nearly a dozen major cybercrime forums since 2019 — including Exploit, Breachforums, Ramp_V2, BHF, Raidforums, and Nulled.
Key findings include:
- Breachforums registration (Jan 2025) came from an IP address in Izhevsk, capital of Russia’s Udmurt Republic.
- Zeta88’s Breached account (Aug 2022) was also created from a different Izhevsk‑based IP.
- A 2020 Raidforums account tied to the email hastalamuerte1488@protonmail.com.
- The Protonmail address links to a GitHub profile under the name SantaMuerte, which follows and develops malware‑related repositories.
Additional breadcrumbs surfaced through Telegram. In 2020, the user advertised the handle @hastalamuerte18, which Flashpoint associates with Telegram ID 30907522.
Constella Intelligence connected that Telegram ID to the username “bu4vs” and the Russian phone number +7 912 765‑00‑04. Records from leaked Russian government databases tie that number to Alexander Andreevich Yapaev, a 36‑year‑old resident of Izhevsk.
Constella also shows that the same phone number was used to create a Pikabu social media account under the name “4apai18,” and that Yapaev frequently used the email bu4vs@mail.ru — an address linked via Epieos to a LinkedIn profile for Alexander Yapaev, who lists himself as the head of B2B marketing at Uralenergo Udmurtia.
Yapaev did not respond to repeated requests for comment.
Why So Many Russian Cybercriminals Leave Clues Behind
Readers often wonder why so many Russian‑speaking cybercriminals appear careless about hiding their identities. Several factors contribute:
- Many did not begin as hardened criminals; they grew into the role gradually as their technical skills improved.
- Russia’s government typically ignores or co‑opts domestic cybercriminals as long as they avoid targeting Russian entities.
- Early in their careers, hackers often make basic operational security mistakes before they understand the risks.
Hastalamuerte’s early forum posts from 2019–2020 reflect this learning curve. In mid‑2020, for example, they joined a months‑long penetration‑testing training program on Telegram, where their messages show them struggling with common security tools — a far cry from the polished operator they appear to be today.
Reward this post with your reaction or TipDrop:
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
TipDrop
0










