TheGentlemen ransomware claims Auren victim
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
Ransomware group 'thegentlemen' lists Auren as a victim, citing exposed FortiOS SSL-VPN credentials tied to the FortiBleed flaw.
Ransomware.live tracked a victim listing for Auren attributed to a ransomware operation known as 'thegentlemen'. The entry, sourced from a leak-site tracker, reports compromise indicators including 3 compromised employees, 30 compromised users, 20 third-party employee credential exposures, and 10 external attack surface findings for the victim's domain.
Notably, the listing states that FortiOS SSL-VPN credentials belonging to the victim's domain were exposed via the 'FortiBleed' leak, associated with CVE-2022-40684 (a Fortinet FortiOS/FortiProxy authentication bypass vulnerability). This suggests initial access or credential exposure may be linked to unpatched or previously compromised Fortinet VPN appliances. Defenders operating FortiOS/FortiProxy devices should verify patch status against CVE-2022-40684, rotate SSL-VPN credentials, and review logs for anomalous authentication events, especially where credentials may have been previously harvested via infostealer infections as referenced in the source's sponsor content.
No further technical detail, ransomware encryption specifics, or TTPs are provided in this listing. This appears to be a leak-site tracking entry rather than a full incident report; defenders in industries connected to Auren or using similar Fortinet infrastructure should prioritize credential rotation and exposure checks.
Mentioned in this report
Detection guidance
1 detections for this report are in the app — rules that match its indicators, converted to Splunk SPL, Microsoft KQL and Elastic, plus YARA and Suricata. Three days of it free, no card.
Source reporting: https://www.ransomware.live/id/QXVyZW5AdGhlZ2VudGxlbWVu
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 11,367 reports from 154 sources, 2,147 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs