Signal

Gentlemen ransomware linked to SystemBC botnet amid rising multi-platform ransomware threats

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-04-20 17:14 UTCUpdated 2026-04-21 18:18 UTC
rss
cveexploitsmalwareransomwareincident_response
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (4 domains)domains are deduped. counts indicate coverage, not truth.
4 top sources shown
SystemBC botnet linked to Gentlemen ransomware attacks
SC Media · News · scworld.com · 2026-04-21 14:30 UTC
The Gentlemen Ransomware Expands With Rapid Affiliate Growth
Infosecurity Magazine · News · infosecurity-magazine.com · 2026-04-21 14:00 UTC
Overview

The Gentlemen ransomware-as-a-service (RaaS) operation, active since mid-2025, has rapidly expanded its affiliate network and targets multiple platforms including Windows, Linux, and VMware ESXi hypervisors.

Entities
Check PointRapid7Gentlemen ransomwareSystemBCKyber ransomwareAnna Širokova
Score total
1.4
Momentum 24h
4
Posts
4
Origins
4
Source types
1
Duplicate ratio
0%
Why now
  • Rapid growth of Gentlemen ransomware affiliates expands attack surface rapidly.
  • Discovery of over 1,570 victims highlights scale and urgency of SystemBC-linked infections.
  • Recent incident response cases reveal Kyber ransomware's sophisticated dual-platform deployment.
Why it matters
  • Gentlemen ransomware's use of SystemBC proxy malware enables widespread multi-platform infections.
  • Kyber ransomware's dual targeting of Windows and ESXi increases risk of total operational disruption.
  • Understanding these threats aids in prioritizing defenses for critical virtualization infrastructure.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
  • Gentlemen ransomware uses SystemBC proxy malware to infect multiple platforms including Windows, Linux, and ESXi.
  • SystemBC command-and-control infrastructure reveals a botnet with over 1,570 victims linked to Gentlemen ransomware.
  • Kyber ransomware targets both Windows and VMware ESXi environments with dual payloads causing significant operational disruption.
How sources frame it
  • SC Media: neutral
  • Infosecurity Magazine: neutral
  • The Hacker News: neutral
  • Rapid7 Blog: neutral
All evidence
All evidence
SystemBC C2 Server Reveals 1,570+ Victims in The Gentlemen Ransomware Operation
The Hacker News · thehackernews.com · 2026-04-21 18:18 UTC
SystemBC botnet linked to Gentlemen ransomware attacks
SC Media · scworld.com · 2026-04-21 14:30 UTC
Kyber Ransomware Double Trouble: Windows and ESXi Attacks Explained
Rapid7 Blog · rapid7.com · 2026-04-21 14:15 UTC
The Gentlemen Ransomware Expands With Rapid Affiliate Growth
Infosecurity Magazine · infosecurity-magazine.com · 2026-04-21 14:00 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 4Origin domains: 4Duplicates: -
Showing 4 / 0
Top publishers (this list)
  • The Hacker News (1)
  • SC Media (1)
  • Rapid7 Blog (1)
  • Infosecurity Magazine (1)
Top origin domains (this list)
  • thehackernews.com (1)
  • scworld.com (1)
  • rapid7.com (1)
  • infosecurity-magazine.com (1)