VORANT. Threat Intelligence Sign in Get the full feed

TheGentlemen ransomware lists Angola's Grupolider

high threat

Angolan agribusiness conglomerate Grupolider has been listed as a victim by the 'TheGentlemen' ransomware group, with exposed FortiOS VPN credentials and infostealer-harvested logins found on its domain.

Ransomware.live's tracking site has added Grupolider, a diversified Angolan holding company (agriculture, logistics, construction, furniture) whose flagship unit Novagrolider is the country's largest agricultural producer, as a victim of the ransomware group operating under the alias 'TheGentlemen'. The entry is flagged as a possible duplicate of another database record, so defenders should treat the attribution and timeline with some caution pending further corroboration.

Supporting exposure data compiled by third-party scanners (HudsonRock and ParanoidLab) shows the organization has a meaningful external attack surface: 4 compromised user accounts and 11 third-party employee credentials surfaced via infostealer logs, plus 751 exposed passwords (219 flagged critical) associated with the domain. Most notably, the domain's FortiOS SSL-VPN credentials were found exposed via the 'FortiBleed' leak, tied to CVE-2022-40684, an unauthenticated path-traversal vulnerability in FortiOS/FortiProxy that allows retrieval of arbitrary system files, including admin credentials, and has been actively exploited since 2022.

For defenders, the combination of long-standing infostealer credential exposure and an unpatched/leaked FortiGate SSL-VPN vulnerability represents a plausible initial-access vector consistent with ransomware intrusions. Organizations using FortiOS/FortiProxy should verify patch status against CVE-2022-40684, rotate any VPN credentials that may have been exposed via this vulnerability, and review infostealer-derived credential exposure for employees and third parties tied to the domain grupolider-ao.com.

Mentioned in this report

Vulnerabilities CVE-2022-40684KEV
Threat actors The Gentlemen
Malware Gentlemen

Detection guidance

1 detection artefacts for this report are available to subscribers.

Source reporting: https://www.ransomware.live/id/R3J1cG9saWRlckB0aGVnZW50bGVtZW4=

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free