# TheGentlemen ransomware lists Angola's Grupolider

Published: 2026-09-21 · Severity: high
Canonical: https://vorant.io/reports/8386c7a8-c376-5c57-b2b3-83243cfe3986/thegentlemen-ransomware-lists-angola-s-grupolider

> Angolan agribusiness conglomerate Grupolider has been listed as a victim by the 'TheGentlemen' ransomware group, with exposed FortiOS VPN credentials and infostealer-harvested logins found on its domain.

Ransomware.live's tracking site has added Grupolider, a diversified Angolan holding company (agriculture, logistics, construction, furniture) whose flagship unit Novagrolider is the country's largest agricultural producer, as a victim of the ransomware group operating under the alias 'TheGentlemen'. The entry is flagged as a possible duplicate of another database record, so defenders should treat the attribution and timeline with some caution pending further corroboration.

Supporting exposure data compiled by third-party scanners (HudsonRock and ParanoidLab) shows the organization has a meaningful external attack surface: 4 compromised user accounts and 11 third-party employee credentials surfaced via infostealer logs, plus 751 exposed passwords (219 flagged critical) associated with the domain. Most notably, the domain's FortiOS SSL-VPN credentials were found exposed via the 'FortiBleed' leak, tied to CVE-2022-40684, an unauthenticated path-traversal vulnerability in FortiOS/FortiProxy that allows retrieval of arbitrary system files, including admin credentials, and has been actively exploited since 2022.

For defenders, the combination of long-standing infostealer credential exposure and an unpatched/leaked FortiGate SSL-VPN vulnerability represents a plausible initial-access vector consistent with ransomware intrusions. Organizations using FortiOS/FortiProxy should verify patch status against CVE-2022-40684, rotate any VPN credentials that may have been exposed via this vulnerability, and review infostealer-derived credential exposure for employees and third parties tied to the domain grupolider-ao.com.

## Mentioned in this report

- Vulnerabilities: CVE-2022-40684 (KEV)
- Threat actors: The Gentlemen
- Malware: Gentlemen

1 more detection artefacts for this report (IOC-atomic rules, Splunk/KQL/Elastic conversions, YARA, Suricata) are available to subscribers.

Source reporting: https://www.ransomware.live/id/R3J1cG9saWRlckB0aGVnZW50bGVtZW4=

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/8386c7a8-c376-5c57-b2b3-83243cfe3986/thegentlemen-ransomware-lists-angola-s-grupolider.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
