TheGentlemen ransomware lists Angola's Grupolider
Angolan agribusiness conglomerate Grupolider has been listed as a victim by the 'TheGentlemen' ransomware group, with exposed FortiOS VPN credentials and infostealer-harvested logins found on its domain.
Ransomware.live's tracking site has added Grupolider, a diversified Angolan holding company (agriculture, logistics, construction, furniture) whose flagship unit Novagrolider is the country's largest agricultural producer, as a victim of the ransomware group operating under the alias 'TheGentlemen'. The entry is flagged as a possible duplicate of another database record, so defenders should treat the attribution and timeline with some caution pending further corroboration.
Supporting exposure data compiled by third-party scanners (HudsonRock and ParanoidLab) shows the organization has a meaningful external attack surface: 4 compromised user accounts and 11 third-party employee credentials surfaced via infostealer logs, plus 751 exposed passwords (219 flagged critical) associated with the domain. Most notably, the domain's FortiOS SSL-VPN credentials were found exposed via the 'FortiBleed' leak, tied to CVE-2022-40684, an unauthenticated path-traversal vulnerability in FortiOS/FortiProxy that allows retrieval of arbitrary system files, including admin credentials, and has been actively exploited since 2022.
For defenders, the combination of long-standing infostealer credential exposure and an unpatched/leaked FortiGate SSL-VPN vulnerability represents a plausible initial-access vector consistent with ransomware intrusions. Organizations using FortiOS/FortiProxy should verify patch status against CVE-2022-40684, rotate any VPN credentials that may have been exposed via this vulnerability, and review infostealer-derived credential exposure for employees and third parties tied to the domain grupolider-ao.com.
Mentioned in this report
Detection guidance
1 detection artefacts for this report are available to subscribers.
Source reporting: https://www.ransomware.live/id/R3J1cG9saWRlckB0aGVnZW50bGVtZW4=
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free