ctipilot.ch

Home · Briefs · CTI Weekly Summary — 2026-W21 (Mon 18 – Sun 24, 2026)

"The Gentlemen" RaaS — communications overhaul underway; operations continuing post-database-leak [SINGLE-SOURCE: Check Point]

From CTI Weekly Summary — 2026-W21 (Mon 18 – Sun 24, 2026) · published 2026-05-18

As of 2026-05-14, Check Point published full analysis of the leaked 16.22 GB "Rocket" database. Administrator zeta88 announced a communications-infrastructure overhaul (new Tor addresses, new affiliate channels) rather than shutdown — the operator is actively hardening against exposure rather than exiting. Bedrock Safeguard's decryptor covered the pre-patch binary; the operator has claimed to patch the binary. Continued victim activity is expected. No new victim disclosures or Tor-address confirmations surfaced in W21 research; watch for new DLS address announcement.