VORANT. Threat Intelligence Sign in Get the full feed

Ransomware.live lists new Gentlemen victim

low threat

A ransomware.live victim entry references a group calling itself "The Gentlemen," but the listing contains no verifiable victim or technical details.

This record is a bare victim listing from the ransomware.live tracking site, referencing a leak-site entry associated with a group identifying as "The Gentlemen." The page itself contains only boilerplate disclaimer text about the platform's data-collection policy and a note that DNS records were found for the victim's domain, with no actual victim name, sector, ransom demand, or technical intrusion details disclosed in the source material.

Because the underlying content (victim identity, timeline, and any exfiltrated data) is not present in this article, no meaningful assessment of scope, targeting, or technique can be made. This entry should be treated as a placeholder pointing to a ransomware leak-site posting rather than a substantive intelligence report; analysts should consult the live ransomware.live page directly for any updated victim or claim details.

Mentioned in this report

Threat actors The Gentlemen
Malware The Gentlemen

Source reporting: https://www.ransomware.live/id/U2lybEB0aGVnZW50bGVtZW4=

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free