Signal
The Gentlemen ransomware leverages SystemBC botnet for corporate-targeted attacks
Evidence first: scan the strongest sources, then decide whether to go deeper.
Published 2026-04-20 12:55 UTCUpdated 2026-04-20 20:02 UTC
rss
ransomwaremalwarethreat_actorsincident_responsesecurity_advisory
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.2 top sources shown
limited source diversity in top sources
Overview
The Gentlemen ransomware-as-a-service (RaaS) operation, active since mid-2025, has rapidly expanded its reach with over 320 victims reported, predominantly corporate entities.
Entities
The GentlemenSystemBC
Score total
1.01
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
Why now
- The rapid increase in victims in early 2026 signals escalating threat activity from The Gentlemen RaaS.
- Recent incident response findings reveal new tactics involving SystemBC, indicating evolving attacker sophistication.
- Understanding this threat helps organizations prepare defenses against multi-platform ransomware attacks.
Why it matters
- The integration of SystemBC proxy malware enhances The Gentlemen ransomware's stealth and delivery capabilities.
- Targeting multiple platforms increases the attack surface in corporate environments, raising risk for diverse organizations.
- The large botnet size indicates a widespread and coordinated campaign against high-value corporate victims.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
- The Gentlemen ransomware-as-a-service has over 320 victims, mostly corporate, with 240 attacks in early 2026.
- SystemBC proxy malware botnet of more than 1,570 hosts is used by The Gentlemen affiliates for covert tunneling and payload delivery.
How sources frame it
- BleepingComputer: neutral
- Check Point Research: neutral
This briefing highlights the growing sophistication of The Gentlemen ransomware group through its use of SystemBC proxy malware, emphasizing the importance of multi-platform defense strategies.
All evidence
All evidence
The Gentlemen ransomware now uses SystemBC for bot-powered attacks
bleepingcomputer_all · bleepingcomputer.com · 2026-04-20 20:02 UTC
DFIR Report – The Gentlemen & SystemBC: A Sneak Peek Behind the Proxy
Check Point Research · research.checkpoint.com · 2026-04-20 12:55 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
- bleepingcomputer_all (1)
- Check Point Research (1)
Top origin domains (this list)
- bleepingcomputer.com (1)
- research.checkpoint.com (1)