Signal
Gentlemen ransomware linked to SystemBC botnet amid rising multi-platform ransomware threats
Evidence first: scan the strongest sources, then decide whether to go deeper.
Published 2026-04-20 17:14 UTCUpdated 2026-04-21 18:18 UTC
rss
cveexploitsmalwareransomwareincident_response
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (4 domains)domains are deduped. counts indicate coverage, not truth.4 top sources shown
Overview
The Gentlemen ransomware-as-a-service (RaaS) operation, active since mid-2025, has rapidly expanded its affiliate network and targets multiple platforms including Windows, Linux, and VMware ESXi hypervisors.
Entities
Check PointRapid7Gentlemen ransomwareSystemBCKyber ransomwareAnna Širokova
Score total
1.4
Momentum 24h
4
Posts
4
Origins
4
Source types
1
Duplicate ratio
0%
Why now
- Rapid growth of Gentlemen ransomware affiliates expands attack surface rapidly.
- Discovery of over 1,570 victims highlights scale and urgency of SystemBC-linked infections.
- Recent incident response cases reveal Kyber ransomware's sophisticated dual-platform deployment.
Why it matters
- Gentlemen ransomware's use of SystemBC proxy malware enables widespread multi-platform infections.
- Kyber ransomware's dual targeting of Windows and ESXi increases risk of total operational disruption.
- Understanding these threats aids in prioritizing defenses for critical virtualization infrastructure.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
- Gentlemen ransomware uses SystemBC proxy malware to infect multiple platforms including Windows, Linux, and ESXi.
- SystemBC command-and-control infrastructure reveals a botnet with over 1,570 victims linked to Gentlemen ransomware.
- Kyber ransomware targets both Windows and VMware ESXi environments with dual payloads causing significant operational disruption.
How sources frame it
- SC Media: neutral
- Infosecurity Magazine: neutral
- The Hacker News: neutral
- Rapid7 Blog: neutral
All evidence
All evidence
SystemBC C2 Server Reveals 1,570+ Victims in The Gentlemen Ransomware Operation
The Hacker News · thehackernews.com · 2026-04-21 18:18 UTC
SystemBC botnet linked to Gentlemen ransomware attacks
SC Media · scworld.com · 2026-04-21 14:30 UTC
Kyber Ransomware Double Trouble: Windows and ESXi Attacks Explained
Rapid7 Blog · rapid7.com · 2026-04-21 14:15 UTC
The Gentlemen Ransomware Expands With Rapid Affiliate Growth
Infosecurity Magazine · infosecurity-magazine.com · 2026-04-21 14:00 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 4Origin domains: 4Duplicates: -
Showing 4 / 0
Top publishers (this list)
- The Hacker News (1)
- SC Media (1)
- Rapid7 Blog (1)
- Infosecurity Magazine (1)
Top origin domains (this list)
- thehackernews.com (1)
- scworld.com (1)
- rapid7.com (1)
- infosecurity-magazine.com (1)