{"id":15613,"date":"2026-06-10T22:15:50","date_gmt":"2026-06-10T22:15:50","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=15613"},"modified":"2026-06-10T22:15:50","modified_gmt":"2026-06-10T22:15:50","slug":"who-runs-the-ransomware-group-the-gents-krebs-on-safety","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=15613","title":{"rendered":"Who Runs the Ransomware Group \u2018The Gents?\u2019 \u2013 Krebs on Safety"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>A cybercrime group often known as <strong>The Gents<\/strong> has emerged because the second most lively ransomware gang by sufferer depend, quickly attracting a gifted pool of hackers via an aggressive recruitment technique that guarantees associates 90 % of any ransom paid by victims. This put up examines clues pointing to an actual life identification for the administrator of The Gents ransomware group.<\/p>\n<div id=\"attachment_73785\" style=\"width: 757px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" aria-describedby=\"caption-attachment-73785\" decoding=\"async\" class=\" wp-image-73785\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/06\/thegentlemen.png\" alt=\"\" width=\"747\" height=\"492\"\/><\/p>\n<p id=\"caption-attachment-73785\" class=\"wp-caption-text\">A graphic created and shared by The Gents ransomware group administrator Hastalamuerte on Breachforums in Might 2026. Credit score: ke-la.com.<\/p>\n<\/div>\n<p>Specialists on the safety agency <strong>Examine Level Software program<\/strong> have been intently protecting exploits of The Gents, a so-called \u201cransomware-as-a-service\u201d (RaaS) providing that pays associates handsomely to assist unfold the group\u2019s malware.<\/p>\n<p>\u201cA 90\/10 affiliate income break up \u2014 in comparison with the trade normal 80\/20 \u2014 is accelerating the group\u2019s progress by attracting skilled operators from competing applications,\u201d the researchers wrote in April.<\/p>\n<p>Examine Level <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/research.checkpoint.com\/2026\/thus-spoke-the-gentlemen\/\" target=\"_blank\" rel=\"noopener\">discovered<\/a> The Gents are the second most lively ransomware group by sufferer depend to this point this yr, claiming a minimum of 332 revealed victims because the group\u2019s inception in mid-2025 and greater than 240 in 2026 alone.<\/p>\n<p>In response to Examine Level, the group targets Web-facing gadgets (VPNs, firewalls) as their entry level, and as soon as inside strikes rapidly to encrypt whole networks inside hours.<\/p>\n<p>Examine Level says the administrator and first operator of the ransomware group makes use of the nickname <strong>Zeta88<\/strong> on the Russian-language cybercrime boards, and that this particular person was beforehand recognized below the moniker <strong>Hastalamuerte<\/strong>. Examine Level famous that <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.kelacyber.com\/blog\/the-gentlemen-ransomware-internal-chat-leak-analysis-2026\/\" target=\"_blank\" rel=\"noopener\">a breach<\/a> of the group\u2019s backend infrastructure made it clear that Hastalamuerte\/Zeta88 is the one that assembles the locker and RaaS panel, manages funds, and is actually the administrator of your entire program who receives 10 % of all ransoms.<span id=\"more-73768\"\/><\/p>\n<h2>WHO IS HASTALAMUERTE?<\/h2>\n<p>The cyber intelligence agency <strong>Intel 471<\/strong> reveals that the person Hastalamuerte is a Russian and English talking one who registered on virtually a dozen cybercrime boards between 2019 and the current day, together with Exploit, Breachforums, Ramp_V2, BHF, <strong>Raidforums<\/strong>, and <strong>Nulled<\/strong>.<\/p>\n<p>Intel 471 reveals that Hastalamuerte registered on Breachforums in January 2025 from an Web deal with in <strong>Izhevsk<\/strong>, the capital metropolis of Russia\u2019s Udmurt Republic. Likewise, the person <strong>Zeta88<\/strong> signed up on the English-language cybercrime discussion board Breached in August 2022 from a special Web deal with in Izhevsk.<\/p>\n<p>Intel 471 finds Hastalamuerte registered on Raidforums in 2020 utilizing the e-mail deal with <strong>hastalamuerte1488@protonmail.com <\/strong>(1488 is a typical mixture of <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/en.wikipedia.org\/wiki\/Fourteen_Words\" target=\"_blank\" rel=\"noopener\">two numeric symbols related to white supremacy<\/a>). A lookup on this deal with on the open supply intelligence service <strong>Epieos<\/strong> reveals it&#8217;s linked to an account at Apple and to a telephone quantity ending in <strong>04<\/strong>.<\/p>\n<p>Epieos says that Protonmail deal with can be linked to a GitHub account below the username <strong>SantaMuerte<\/strong>. That account is marked non-public, however <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/connectionrequired.com\/gitspective\/#\/timeline\/SantaLaMuerte\" target=\"_blank\" rel=\"noopener\">a historical past of this person\u2019s exercise<\/a> reveals they&#8217;re watching and creating quite a lot of malware instruments and exploits.<\/p>\n<p>In April 2020, Hastalamuerte mentioned on the crime discussion board Nulled that they may very well be contacted on the Telegram instantaneous messenger identify <strong>@hastalamuerte18<\/strong>, and the risk intelligence firm <strong>Flashpoint<\/strong> finds this username is assigned the distinctive Telegram ID quantity <strong>30907522 <\/strong>[full disclosure: Flashpoint is an advertiser on this blog].<\/p>\n<p>The breach monitoring service <strong>Constella Intelligence<\/strong> experiences that Hastalamuerte\u2019s Telegram ID is linked to a different username \u2014 \u201c<strong>bu4vs<\/strong>\u201d \u2014 and to the Russian telephone quantity <strong>79127650004<\/strong>. Pivoting on this telephone quantity in Constella fetches a number of information from hacked Russian authorities databases exhibiting it&#8217;s assigned to at least one <strong>Alexander Andreevich Yapaev<\/strong>, a 36-year-old from Izhevsk.<\/p>\n<p>Constella reveals that telephone quantity was used to create an account on the Russian social media platform Pikabu below the identify \u201c<strong>4apai18<\/strong>,\u201d and reveals Mr. Yapaev has signed up at quite a lot of web sites utilizing the frequent surname <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/bu4vs\/status\/235798656769470465\" target=\"_blank\" rel=\"noopener\">Ivanov<\/a>, or else \u201cChapaev\u201d (the numeral 4 is commonly used as shorthand for a \u201cch\u201d sound in Russian).<\/p>\n<p>A search in Intel 471 for cybercrime discussion board members with the nickname SantaMeurte finds an account by the identical identify created in 2020 on the Russian hacking discussion board Codeby. Intel 471 reveals this person initially registered on Codeby with the not-so-subtle nickname <strong>Alexandr 4apaev<\/strong>.<\/p>\n<p>Constella finds Mr. Yapaev recurrently used the e-mail deal with <strong>bu4vs@mail.ru<\/strong>. In the meantime, Epieos reveals this deal with is linked to a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.linkedin.com\/in\/yapaev\/\" target=\"_blank\" rel=\"noopener\">LinkedIn account<\/a> for Alexander Yapaev, who lists himself as the top of B2B advertising on the firm <strong>Uralenergo Udmurtia<\/strong>, considered one of Russia\u2019s largest suppliers of electrotechnical and lighting merchandise.<\/p>\n<p>Mr. Yapaev didn&#8217;t reply to a number of requests for remark.<\/p>\n<p>Almost each time we publish considered one of these <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/category\/breadcrumbs\/\" target=\"_blank\" rel=\"noopener\">Breadcrumbs tales<\/a>, readers are curious to know why it looks as if so many cybercriminals from Russia apparently do little to cover their actual life identities. The reality is that \u2014 Russian or not \u2014 most didn\u2019t precisely got down to be arch criminals, however as a substitute bought drawn into the scene step by step over a number of years as their abilities broadened and sharpened.<\/p>\n<p>One other necessary dynamic is that the Russian authorities usually both <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.recordedfuture.com\/research\/dark-covenant-3-controlled-impunity-and-russias-cybercriminals\" target=\"_blank\" rel=\"noopener\">co-opts or ignores<\/a> cybercriminal exercise inside its border as long as the hackers don&#8217;t steal from or assault Russian companies and residents. In consequence, profitable cybercriminals in Russia are often insulated from prosecution and arrest by international regulation enforcement companies supplied they sometimes repay the fitting folks and don&#8217;t journey overseas. And cybercriminals who intend to strictly adhere to these unwritten guidelines could (a minimum of initially) be much less involved about protecting their tracks on-line.<\/p>\n<p>However the easiest rationalization is that cybercriminals of all nationalities are likely to make quite a lot of primary operational safety errors early of their careers, when they&#8217;re much less savvy and have far much less to lose by their carelessness. A evaluation of Hastalamuerte\u2019s early posts on the crime boards (circa 2019-2020) reveals a comparatively unsophisticated and low-skilled hacker nonetheless attempting to study the ropes and earn a optimistic fame on these communities.<\/p>\n<p>For instance, in June 2020 Hastalamuerte\u2019s Telegram account joined a multi-month coaching program (@pntst) to discover ways to use common penetration testing instruments, and their candid posts to this hacker coaching camp present Hastalamuerte struggling to make use of these instruments successfully. A Google-translated document of Hastalmuerte\u2019s posts to @pntst is <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/06\/pntst-chat.txt\" target=\"_blank\" rel=\"noopener\">right here<\/a>.<\/p>\n<\/p><\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>A cybercrime group often known as The Gents has emerged because the second most lively ransomware gang by sufferer depend, quickly attracting a gifted pool of hackers via an aggressive recruitment technique that guarantees associates 90 % of any ransom paid by victims. This put up examines clues pointing to an actual life identification for [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":15615,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[9380,853,262,500,1746,211],"class_list":["post-15613","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-gentlemen","tag-group","tag-krebs","tag-ransomware","tag-runs","tag-security"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15613","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=15613"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15613\/revisions"}],"predecessor-version":[{"id":15614,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15613\/revisions\/15614"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/15615"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=15613"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=15613"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=15613"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-11 18:15:58 UTC -->