INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Gentlemen ransomware now uses SystemBC for bot-powered attacks
| 2026-04-20 20:02 HIGH LOW RANSOMWARE & EXTORTION DATA BREACH
Executive Summary
AI-generated
In December 2025, the Gentlemen ransomware compromised one of Romania's largest energy providers, Oltenia Energy Complex. The attackers are believed to be affiliated with a gang that has been linked to victims in the United States, the United Kingdom, Germany, Australia, and Romania, totaling over 1,570 hosts. The Gentlemen ransomware now uses SystemBC for bot-powered attacks, utilizing SOCKS5 tunneling capabilities to deliver malicious payloads. A recent investigation revealed an affiliate's attempt to deploy a proxy malware botnet, which was discovered following the attack on Oltenia Energy Complex. Currently, Check Point researchers are unsure how SystemBC fits into Gentlemen ransomware's ecosystem and could not determine if the malware was used by multiple affiliates.
Technical Mitigations AI-generated
• Block or hunt for SystemBC proxy malware botnets, specifically targeting the SOCKS5 tunneling capability.
• Patch vulnerable systems by updating to a version of ESXi that is not susceptible to the Gentlemen ransomware's C-based locker attack vector.
• Use XChaCha20 and X25519 encryption schemes with caution, as they are used by Gentlemen ransomware for hybrid encryption.
• Implement Mimikatz detection techniques to prevent credential harvesting attacks.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Cobalt StrikeCobalt Strike
Target & Sectors
FIVE_EYES
FIVE_EYES
energyenergy
Incident Timeline
2026/04/20
The Gentlemen ransomware now uses SystemBC for bot-powered attacks.
Click on any entity below to view its context and source!
infrastructure
1,570 hosts
A SystemBC proxy malware botnet of more than 1,570 hosts, believed to be corporate victims, has been discovered following an investigation into a Gentlemen ransomware attack carried out by a gang affiliate.
The researchers believe that using SystemBC with Cobalt Strike and the botnet of 1,570 hosts may indicate that the Gentlemen ransomware gang is now operating at a higher level, "actively integrating into a broader toolchain of mature, post‑exploit…
infrastructure
Windows
The Gentlemen ransomware-as-a-service (RaaS) operation emerged around mid-2025 and provides a Go-based locker that can encrypt Windows, Linux, NAS, and BSD systems, and a C-based locker for ESXi hypervisors.
infrastructure
Linux
The Gentlemen ransomware-as-a-service (RaaS) operation emerged around mid-2025 and provides a Go-based locker that can encrypt Windows, Linux, NAS, and BSD systems, and a C-based locker for ESXi hypervisors.
victims
320 victims
Although the RaaS operation has publicly claimed around 320 victims, most of the attacks occurring this year, Check Point researchers discovered that the Gentlemen ransomware affiliates are expanding their attack toolkit and infrastructure.
infrastructure
1,500 commercial virtual private servers
Despite a
law enforcement operation
that affected it in 2024, the botnet remains active, and last year
Black Lotus Labs reported
that it was infecting 1,500 commercial virtual private servers (VPS) every day to funnel malicious traffic.
victims
1,570 victims
…Point Research observed victim telemetry from the relevant SystemBC command‑and‑control server, revealing a botnet of over 1,570 victims, with the infection profile strongly suggesting a focus on corporate and organizational environments rather th…
data_breach
1 MB
Files under 1 MB are fully encrypted, while with larger files only chunks of data of about 9%, 3%, or 1% were encrypted.
Tactical Metrics
Metrics
infrastructure
1,570
Hosts
Click for context!
A SystemBC proxy malware botnet of more than 1,570 hosts, believed to be corporate victims, has been discovered following an investigation into a Gentlemen ransomware attack carried out by a gang affiliate.
The researchers believe that using SystemBC with Cobalt Strike and the botnet of 1,570 hosts may indicate that the Gentlemen ransomware gang is now operating at a higher level, "actively integrating into a broader toolchain of mature, post‑exploit…
Metrics
infrastructure
Windows
Affected Product
The Gentlemen ransomware-as-a-service (RaaS) operation emerged around mid-2025 and provides a Go-based locker that can encrypt Windows, Linux, NAS, and BSD systems, and a C-based locker for ESXi hypervisors.
Metrics
infrastructure
Linux
Affected Product
The Gentlemen ransomware-as-a-service (RaaS) operation emerged around mid-2025 and provides a Go-based locker that can encrypt Windows, Linux, NAS, and BSD systems, and a C-based locker for ESXi hypervisors.
Metrics
victims
320
Victims
Although the RaaS operation has publicly claimed around 320 victims, most of the attacks occurring this year, Check Point researchers discovered that the Gentlemen ransomware affiliates are expanding their attack toolkit and infrastructure.
Metrics
victims
1,570
Victims
…Point Research observed victim telemetry from the relevant SystemBC command‑and‑control server, revealing a botnet of over 1,570 victims, with the infection profile strongly suggesting a focus on corporate and organizational environments rather th…
Metrics
infrastructure
1,500
Commercial Virtual Private Servers
Despite a
law enforcement operation
that affected it in 2024, the botnet remains active, and last year
Black Lotus Labs reported
that it was infecting 1,500 commercial virtual private servers (VPS) every day to funnel malicious traffic.
Metrics
data_breach
1
Mb
Files under 1 MB are fully encrypted, while with larger files only chunks of data of about 9%, 3%, or 1% were encrypted.
Intelligence Sources
BleepingComputer
2026-04-20
The Gentlemen ransomware now uses SystemBC for bot-powered attacks
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T08:43
Comprehensive Tactical Telemetry
Highly Correlated Entities
17x
organisation
Identified Entity
the Oltenia Energy Complex
entity
5x
tactic
Cyber Operation Type
Ransomware
tactic
5x
timeline
Temporal Reference
mid-2025
date
3x
source region
Origin Country
United States
country
3x
general metric
%
9
%
2x
target region
Target Country
Romania
country
2x
infrastructure
Affected Product
Windows
software
2x
victims
Victims
320
victims
2x
malware
Offensive Tool
Cobalt Strike
tool
Contextual Telemetry
Context Block
4 METRICS
infrastructure
Hosts
1,570
hosts
infrastructure
Commercial Virtual Private Servers
1,500
commercial virtual private servers
general metric
May
14
may
data breach
Mb
1
mb
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.