Signal

The Gentlemen ransomware leverages SystemBC botnet for corporate-targeted attacks

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-04-20 12:55 UTCUpdated 2026-04-20 20:02 UTC
rss
ransomwaremalwarethreat_actorsincident_responsesecurity_advisory
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.
2 top sources shown
limited source diversity in top sources
Overview

The Gentlemen ransomware-as-a-service (RaaS) operation, active since mid-2025, has rapidly expanded its reach with over 320 victims reported, predominantly corporate entities.

Entities
The GentlemenSystemBC
Score total
1.01
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
Why now
  • The rapid increase in victims in early 2026 signals escalating threat activity from The Gentlemen RaaS.
  • Recent incident response findings reveal new tactics involving SystemBC, indicating evolving attacker sophistication.
  • Understanding this threat helps organizations prepare defenses against multi-platform ransomware attacks.
Why it matters
  • The integration of SystemBC proxy malware enhances The Gentlemen ransomware's stealth and delivery capabilities.
  • Targeting multiple platforms increases the attack surface in corporate environments, raising risk for diverse organizations.
  • The large botnet size indicates a widespread and coordinated campaign against high-value corporate victims.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
  • The Gentlemen ransomware-as-a-service has over 320 victims, mostly corporate, with 240 attacks in early 2026.
  • SystemBC proxy malware botnet of more than 1,570 hosts is used by The Gentlemen affiliates for covert tunneling and payload delivery.
How sources frame it
  • BleepingComputer: neutral
  • Check Point Research: neutral
This briefing highlights the growing sophistication of The Gentlemen ransomware group through its use of SystemBC proxy malware, emphasizing the importance of multi-platform defense strategies.
All evidence
All evidence
The Gentlemen ransomware now uses SystemBC for bot-powered attacks
bleepingcomputer_all · bleepingcomputer.com · 2026-04-20 20:02 UTC
DFIR Report – The Gentlemen & SystemBC: A Sneak Peek Behind the Proxy
Check Point Research · research.checkpoint.com · 2026-04-20 12:55 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
  • bleepingcomputer_all (1)
  • Check Point Research (1)
Top origin domains (this list)
  • bleepingcomputer.com (1)
  • research.checkpoint.com (1)