Cyber Security News

New Gentlemen’s RaaS Advertised on Hacking Forums Targeting Windows, Linux and ESXi Systems

A newly discovered ransomware-as-a-service platform called Gentlemen’s RaaS has recently emerged on underground hacking forums, offering threat actors a sophisticated cross-platform attack capability.

The service, advertised by the threat actor known as zeta88, represents a significant expansion in ransomware delivery models, targeting critical infrastructure across multiple operating systems.

This development signals an intensified threat landscape where organized cybercriminals are offering affiliate-based ransomware operations to lower-level attackers, democratizing access to enterprise-level encryption malware.

The service leverages a compelling business model that allocates ninety percent of ransom proceeds to affiliates while retaining just ten percent for the operator.

This generous revenue-sharing arrangement has proven highly attractive to potential partners within the cybercriminal ecosystem.

By offering this financial incentive structure, the platform encourages widespread adoption and rapid deployment across global organizations.

The architecture reflects a deliberate strategy to scale ransomware operations efficiently while maintaining operational control through centralized decryption infrastructure.

KrakenLabs researchers identified the malware following detailed analysis of its promotional materials circulating across hacking forums.

The platform exhibits sophisticated technical construction with separate lockers designed for specific platforms, indicating purpose-built infrastructure rather than generic variants.

Lateral movement

The most technically noteworthy aspect involves the malware’s persistence and lateral movement mechanisms.

Gentlemen’s RaaS deploys a Go-based locker targeting Windows, Linux, NAS, and BSD systems, while employing a separate C-coded ESXi locker approximately thirty-two kilobytes in size.

The encryption implementation utilizes XChaCha20 combined with Curve25519 cryptography, with per-file ephemeral keys providing granular encryption architecture.

Particularly concerning is the self-propagation capability through WMI, WMIC, SCHTASKS, SC, and PowerShell Remoting commands, enabling rapid network traversal.

The malware establishes persistence via schtasks registry modifications and run-on-boot routines, ensuring survival across system restarts and administrative interventions.

Additionally, the platform supports network share discovery and automated encryption, allowing the ransomware to identify and compromise adjacent systems seamlessly.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

China-linked APT24 Hackers New BadAudio Compromised Legitimate Public Websites to Attack Users

APT24, a sophisticated cyber espionage group linked to China's People's Republic, has launched a relentless…

27 minutes ago

Broadcom Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack

The Cl0p ransomware group has claimed responsibility for infiltrating Broadcom's internal systems as part of…

1 hour ago

Critical Grafana Vulnerability Let Attackers Escalate Privilege

Grafana Labs has disclosed a critical security vulnerability affecting Grafana Enterprise that could allow attackers…

1 hour ago

Critical ASUSTOR Vulnerability Let Attackers Execute Malicious Code with Elevated Privileges

A critical security vulnerability has been discovered in ASUSTOR backup and synchronization software, allowing attackers…

2 hours ago

Windows 11 to Hide BSOD Crash Errors on Public Displays

Microsoft has introduced a practical new feature in Windows 11 designed specifically for public-facing monitors…

3 hours ago

SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely

SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That…

6 hours ago