► Who Runs the Ransomware Group ‘The Gentlemen?’ – Krebs on Security
Source: https://krebsonsecurity.com/2026/06/who-runs-the-ransomware-group-the-gentlemen/
Method: legacy
Fetched: 2026-07-31T07:12:30.493467+00:00
IPFS: QmcPHvUxkd95fbfCwEiS... | Open Raw
Cache: Freshly fetched
A cybercrime group known asThe Gentlemenhas emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group.
Experts at the security firmCheck Point Softwarehave been closely covering exploits of The Gentlemen, a so-called “ransomware-as-a-service” (RaaS) offering that pays affiliates handsomely to help spread the group’s malware.
“A 90/10 affiliate revenue split — compared to the industry standard 80/20 — is accelerating the group’s growth by attracting experienced operators from competing programs,” the researchers wrote in April.
Check PointfoundThe Gentlemen are the second most active ransomware group by victim count so far this year, claiming at least 332 published victims since the group’s inception in mid-2025 and more than 240 in 2026 alone.
According to Check Point, the group targets Internet-facing devices (VPNs, firewalls) as their entry point, and once inside moves quickly to encrypt entire networks within hours.
Check Point says the administrator and primary operator of the ransomware group uses the nicknameZeta88on the Russian-language cybercrime forums, and that this individual was previously known under the monikerHastalamuerte. Check Point noted thata breachof the group’s backend infrastructure made it clear that Hastalamuerte/Zeta88 is the person who assembles the locker and RaaS panel, manages payments, and is essentially the administrator of the entire program who receives 10 percent of all ransoms.
WHO IS HASTALAMUERTE?
The cyber intelligence firmIntel 471shows that the user Hastalamuerte is a Russian and English speaking person who registered on almost a dozen cybercrime forums between 2019 and the present day, including Exploit, Breachforums, Ramp_V2, BHF,Raidforums, andNulled.
Intel 471 reveals that Hastalamuerte registered on Breachforums in January 2025 from an Internet address inIzhevsk, the capital city of Russia’s Udmurt Republic. Likewise, the userZeta88signed up at the English-language cybercrime forum Breached in August 2022 from a different Internet address in Izhevsk.
Intel 471 finds Hastalamuerte registered on Raidforums in 2020 using the email addresshastalamuerte1488@protonmail.com(1488 is a common combination oftwo numeric symbols associated with white supremacy). A lookup on this address at the open source intelligence serviceEpieosshows it is connected to an account at Apple and to a phone number ending in04.
Epieos says that Protonmail address is also linked to a GitHub account under the usernameSantaMuerte. That account is marked private, buta history of this user’s activityshows they are watching and developing a number of malware tools and exploits.
In April 2020, Hastalamuerte said on the crime forum Nulled that they could be contacted at the Telegram instant messenger name@hastalamuerte18, and the threat intelligence companyFlashpointfinds this username is assigned the unique Telegram ID number30907522[full disclosure: Flashpoint is an advertiser on this blog].
The breach tracking serviceConstella Intelligencereports that Hastalamuerte’s Telegram ID is connected to another username — “bu4vs” — and to the Russian phone number79127650004. Pivoting on this phone number in Constella fetches multiple records from hacked Russian government databases showing it is assigned to oneAlexander Andreevich Yapaev, a 36-year-old from Izhevsk.
Constella reveals that phone number was used to create an account at the Russian social media platform Pikabu under the name “4apai18,” and shows Mr. Yapaev has signed up at a number of websites using the common surnameIvanov, or else “Chapaev” (the numeral 4 is often used as shorthand for a “ch” sound in Russian).
A search in Intel 471 for cybercrime forum members with the nickname SantaMuerte unearths an account by the same name created in 2020 on the Russian hacking forum Codeby. Intel 471 shows this user originally registered on Codeby with the not-so-subtle nicknameAlexandr 4apaev.
Constella finds Mr. Yapaev regularly used the email addressbu4vs@mail.ru. Meanwhile, Epieos shows this address is connected to aLinkedIn accountfor Alexander Yapaev, who lists himself as the head of B2B marketing at the companyUralenergo Udmurtia, one of Russia’s largest suppliers of electrotechnical and lighting products.
Mr. Yapaev did not respond to multiple requests for comment.
Nearly every time we publish one of theseBreadcrumbs stories, readers are curious to know why it seems like so many cybercriminals from Russia apparently do little to hide their real life identities. The truth is that — Russian or not — most didn’t exactly set out to be arch criminals, but instead got drawn into the scene gradually over several years as their skills broadened and sharpened.
Another important dynamic is that the Russian government generally eitherco-opts or ignorescybercriminal activity within its borders so long as the hackers do not steal from or attack Russian businesses and citizens. As a result, successful cybercriminals in Russia are usually insulated from prosecution and arrest by foreign law enforcement agencies provided they occasionally pay off the right people and do not travel abroad. And cybercriminals who intend to strictly adhere to those unwritten rules may (at least initially) be less concerned about covering their tracks online.
But the simplest explanation is that cybercriminals of all nationalities tend to make a number of basic operational security mistakes early in their careers, when they are less savvy and have far less to lose by their carelessness. A review of Hastalamuerte’s early posts on the crime forums (circa 2019-2020) shows a relatively unsophisticated and low-skilled hacker still trying to learn the ropes and earn a positive reputation on these communities.
For example, in June 2020 Hastalamuerte’s Telegram account joined a multi-month training program (@pntst) to learn how to use popular penetration testing tools, and their candid posts to this hacker training camp show Hastalamuerte struggling to use these tools effectively. A Google-translated record of Hastalmuerte’s posts to @pntst ishere.
Update, June 11, 10:23 a.m. ET:The threat research groupPRODAFThas releaseda detailed writeupon the history and current operations of The Gentlemen. PRODAFT said its findings match the same persona with “high confidence,” and found the administrator (Zeta88/Hastalamuerte) supplies affiliates with initial access directly, primarily Fortinet SSL-VPN credentials obtained through brute-force attacks or sourced from the group’s own leak database. They also discovered the administrator is using AI to develop and maintain the ransomware and associated tooling, as well as to assist with post-exploitation activity.
39 thoughts on “Who Runs the Ransomware Group ‘The Gentlemen?’”
True operational secrecy is a pain in the butt, hard to maintain, and easy to screw up. That’s why it’s better to be able to act in your real name and not have to worry about it…
It’s amazing how these ransomware gangs are able to maintain military intelligence level opsecAlmost as if…
Um, almost as if their business model provides enough income to afford it? Enough with the conspiracy theories. Brian understands that most of these sorts of operations have a learning curve. They are most vulnerable at three or four times in each ransom cycle (three, if it is an established affiliate relationship for long enough to have ascertained they aren’t involved in a sting). Once they figure out how to proxy, manage their toolchain properly, and successfully get ahold of the money they asked for, the only thing left to worry about is how to make it look legitimate. Ransomware removes the long-term upkeep and gradual profit model of a botnet. Now that companies are willing to pay hundreds of thousands or millions per incident, you don’t need to be ‘Russian’ or ‘Ukrainian’, or have connections to any sort of corrupt officials, you just have to throw someone else under the bus faster than the other person, it looks like.
‘able to maintain military intelligence level opsec’Some of them are run by military intelligence in various countries, some of those are very good at it.I don’t think that’s amazing, unbelievable or improbable, nor is it a conspiracy theory. It lines up fine.If you’re trying to imply a _particular_ gang or campaign is run by mil.ops, that requires specificity.Vague implications are like…
Has anyone told Apple about “Hastalamuerte registered on Raidforums in 2020 using the email addresshastalamuerte1488@protonmail.com(1488 is a common combination of two numeric symbols associated with white supremacy). A lookup on this address at the open source intelligence service Epieos shows it is connected to an account at Apple and to a phone number ending in 04.”Can they disable his account?
I don’t see why. He’s not infringing on any of Apple’s terms with his account, nor has he attacked Apple. Simply *being* a criminal shouldn’t get you disbarred from using any services.
“He’s not infringing on any of Apple’s terms with his account, nor has he attacked Apple.”
That _you_ know of? It’s improbable that nobody connected to Apple whatsoever was targeted.I’ve not recently deep-read Apple’s EULA but I’d think *being a criminal* is in there somehow…
lol
Hats off, GENTLEMEN, to Brian Krebs!
It’s funny. When I start reading it, I thought to myself, “Russian?” And sure enough. It is.
I think the reason it’s so easy to track there people down (aside from the Russian government letting them do it as long as the victims are in the West and that’s why they don’t care about hiding) is because most of those “hackers” are just plain stupid low lives. Otherwise anyone that had two brain cells had already left that nasty country.
@Dennis – I think if you have money, are careful and discreet, and stay out of politics… Russia can be a veery pleasant place to live.
Hmmm. Never seemed to work for Arkady Renko.
I live next to Russia. I have friends and ex-colleagues in Russia (we had a branch office in Moscow). I speak Russian, I read Russian literature, I liste n to Russian music.No it is not pleasant place to live. Perhaps if you are very rich so you can live in a secure enclave.There is– corruption, being a daily part of the society on all levels– crime, the same, being constantly present in all places– censorship and surveillance– cynicism that permeates everything
The company ended up dismantling the Moscow office and relocating the staff, on company expenses, to Central Europe.A bank that I worked for tried to expand to Russia. It backed off after a few years – the corruption was unmanageable.Russia has great nature, great culture, and the people are friendly and welcoming. But as a place to live – no, it is not pleasant at all.
I think it most definitely matters where in Russia (or let’s be honest, here, what country near Russia) you are taking about. I think it is dangerous to confuse “low corruption” with “a different sort of corruption”, also. It is shocking how many ignorant people think Ukraine is or was less corrupt, for instance, or really, most any country in Central or Eastern Europe. Might make more sense to judge corruption by whether you wind up getting what you paid for (be it in money, favour, or just looking the other way). Some “corrupt” places, you get treated more fairly than some places people deem ‘fair’. Better a mechanism to work around corruption and bias, to some people, than no recompense or recourse. It might cost, but better that than no alternative.
“Nasty country” – pray tell where you’ve found so entirely free of nastiness to live, Mr. Menace?
Might as well be living on the sun.
He’s got an umbrella and time to kill. It’s a dry heat.
I believe his identity is BIG BALLS! You know the guy that got beat up by a girl in DC and even of more surprise he was on a date with a GIRL.
Seems like something the snowflake orange one would be involved with.
There was some chatter on Telegram about ShinyHunters running The Gentlemen ransomware group, but oh well…
Not the same people, of course. Sort of like suggesting Horohorin is, I dunno, the dude that runs the Krebs carding dump site.
No Doubt!
TIL that WayBackMachine archived Google Plus (RIP) posts..
It’s cute that even Russian ransomware gangs think stuff like… GDPR violations? matter at all in the real world.From reading the Checkpoint article, it definitely seems like we’re finally getting into the era of “AI-powered ransomware”. Not completely “agentic” a la “claude, ransom this company, make no mistakes”, but like… AI-written panels, AI-written ransom notes, and seeing as how quick and badly they got pwned, I’d imagine some local Chinese AI was like “You’re absolutely right, exposing port 445 on your Synology NAS to the clearnet is the most secure way to securely access your files anywhere!” and now we’re here.
This pretty much nulls most textual forensics, too, yeah.
When I lived in Transnistria briefly, many many years ago, there were no ATMs at all. It was a surprisingly genteel place to stay for a week or two to get away from crazies, LGBTQ- obsessed Pussy Riot fans, and tourists, until they made that mean something else entirely. CLEARLY, there was access to legitimate ATMs an easy, cheap train-ride away, until the sheeeyit hit the Kendrick a few months (and many many years) later.
welp! time for my teeth to marry the extension cord again!
Arguably, they should not, merely by the existence of a name, known it was the same person, no less a ‘criminal’, right?
soon the next prod release of Kill Your Celf will push!
Quickly, quickly ai chatbot!
The NSA.WHAT DID I WIN
The same guys who run every ransomware groupThe same guys who run Krebs.Did you use a real russian time?Brian , or is it a synthetic russian?Cant arrest data. Even from the Moscow field office of the FBI
The same guys who run every ransomware groupThe same guys who run Krebs.Did you use a real russian this time?Brian , or is it a synthetic russian?Cant arrest data. Even from the Moscow field office of the FBI
If Yan can’t think then NOBODY IS ALLOWED TO. Off to the reeducation camps like a good lad.
Martin,Go squat in a thorny tree.
What is Martin’s metier, anyway?Krebs isn’t run by any one group of anything any more than you are.
Lots of AI slop puppeting every meatpuppet now (no offense, Brian).
Great breakdown on threat actor attribution. Security research like this is essential for organizations evaluating third-party risk. I run a site covering crypto and financial analysis and send your investigative work to clients regularly as a reference.
Very interesting article, I always say there’s only one internet and there’s residue from everyone on it. And now with AI able to aggregate so much it truly shows that the internet is us and we are the internet. We’ve been building our digital persona for years, our essence is in the very fabric.
Dropping a quick note of appreciation. Superb post.
Rare to see such a balanced take. Appreciate you putting the time into this. Take care.
You turned what’s usually a dry topic into something readable. Saved me hours of digging around.
Comments are closed.
Mailing List
Search KrebsOnSecurity
Recent Posts
Story Categories
Why So Many Top Hackers Hail from Russia
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------