ctipilot.ch

The Gentlemen

actor · actor:thegentlemen single-source

Ransomware-as-a-service operation (also tracked as Storm-2697 / Phantom Mantis) that surged in Q1 2026 — 192 attacks, +588% QoQ, 32% of victims European, with FortiGate CVE-2024-55591 as the initial-access funnel. ESET (2026-06-18) documents the operators centrally building and maintaining the GentleKiller EDR-killer framework (BYOVD, 48 vendors) for their affiliates.

Aliases: Gentlemen RaaS, Storm-2697, Phantom Mantis

Coverage timeline
23
first 2026-05-04 → last 2026-07-12
Peak priority
high
6 high · 17 notable
Sources cited
56
45 hosts
Sections touched
7
active-threats, research, weekly-annual-reports
Co-occurring entities
1
see Related entities below
ATT&CK techniques
10
pinned v19.1 · see below
2026-05-0423 appearances2026-07-12

ATT&CK techniques

10 techniques observed across 4 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-07-12/weekly-w28-the-gentlemen-status · ATT&CK page ↗

Execution TA0002

T1047Windows Management Instrumentation×1

Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems. WMI is an administration feature that provides a uniform environment to access Windows system components.

Evidence: 2026-05-04/akira-playbook-quarterly-context-q1-2026-healthcare-concentr · ATT&CK page ↗

T1053Scheduled Task/Job×1

Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code. Utilities exist within all major operating systems to schedule programs or scripts to be executed at a specified date and time. A task can also be scheduled on a remote system, provided the proper authentication is met (ex: RPC and file and printer sharing in Windows environments). Scheduling a task on a remote system typically may require being a member of an admin or otherwise privileged group on the remote system.

Evidence: 2026-06-12/the-gentlemen-ransomware-478-claimed-leak-site-victims-self · ATT&CK page ↗

T1053.005Scheduled Task/Job: Scheduled Task×1

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-06-12/the-gentlemen-ransomware-478-claimed-leak-site-victims-self · ATT&CK page ↗

Persistence TA0003

T1053Scheduled Task/Job×1

Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code. Utilities exist within all major operating systems to schedule programs or scripts to be executed at a specified date and time. A task can also be scheduled on a remote system, provided the proper authentication is met (ex: RPC and file and printer sharing in Windows environments). Scheduling a task on a remote system typically may require being a member of an admin or otherwise privileged group on the remote system.

Evidence: 2026-06-12/the-gentlemen-ransomware-478-claimed-leak-site-victims-self · ATT&CK page ↗

T1053.005Scheduled Task/Job: Scheduled Task×1

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-06-12/the-gentlemen-ransomware-478-claimed-leak-site-victims-self · ATT&CK page ↗

T1543.003Create or Modify System Process: Windows Service×1

Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.

Evidence: 2026-06-19/eset-the-gentlemen-raas-gang-centrally-builds-and-maintains · ATT&CK page ↗

Privilege Escalation TA0004

T1053Scheduled Task/Job×1

Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code. Utilities exist within all major operating systems to schedule programs or scripts to be executed at a specified date and time. A task can also be scheduled on a remote system, provided the proper authentication is met (ex: RPC and file and printer sharing in Windows environments). Scheduling a task on a remote system typically may require being a member of an admin or otherwise privileged group on the remote system.

Evidence: 2026-06-12/the-gentlemen-ransomware-478-claimed-leak-site-victims-self · ATT&CK page ↗

T1053.005Scheduled Task/Job: Scheduled Task×1

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-06-12/the-gentlemen-ransomware-478-claimed-leak-site-victims-self · ATT&CK page ↗

T1543.003Create or Modify System Process: Windows Service×1

Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.

Evidence: 2026-06-19/eset-the-gentlemen-raas-gang-centrally-builds-and-maintains · ATT&CK page ↗

Defense Impairment TA0112

T1685Disable or Modify Tools×2

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.

Evidence: 2026-07-12/weekly-w28-the-gentlemen-status · 2026-06-12/the-gentlemen-ransomware-478-claimed-leak-site-victims-self · ATT&CK page ↗

Lateral Movement TA0008

T1021Remote Services×2

Adversaries may use Valid Accounts to log into a service that accepts remote connections, such as telnet, SSH, and VNC. The adversary may then perform actions as the logged-on user.

Evidence: 2026-06-12/the-gentlemen-ransomware-478-claimed-leak-site-victims-self · 2026-05-04/akira-playbook-quarterly-context-q1-2026-healthcare-concentr · ATT&CK page ↗

T1021.001Remote Services: Remote Desktop Protocol×1

Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.

Evidence: 2026-05-04/akira-playbook-quarterly-context-q1-2026-healthcare-concentr · ATT&CK page ↗

T1021.002Remote Services: SMB/Windows Admin Shares×1

Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB). The adversary may then perform actions as the logged-on user.

Evidence: 2026-06-12/the-gentlemen-ransomware-478-claimed-leak-site-victims-self · ATT&CK page ↗

Impact TA0040

T1486Data Encrypted for Impact×1

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-07-12/weekly-w28-the-gentlemen-status · ATT&CK page ↗

Story timeline

  1. 2026-07-12The Gentlemen (Storm-2697) status update — Unit 42's full profile: 580 victims, a Qilin-affiliate lineage, and a suspected EDR-disable zero-day
    weekly-long-runningThe Gentlemen status update — Unit 42 profiles 580 victims/77 countries, ArmCorp/Qilin lineage, 90% affiliate cut, suspected EDR-disable zero-day
  2. 2026-07-12Looking ahead — 2026-W28
    weekly-looking-aheadLooking ahead — 2026-W28: items already in motion for the coming weeks
  3. 2026-06-29The Gentlemen
    weekly-long-running
  4. 2026-06-29ESET "Killing me gently" — a de-facto mid-year RaaS-tooling report
    weekly-annual-reports
  5. 2026-06-27"The Gentlemen" ransomware claims 478 victims and adds worm propagation — Switzerland the second-most-targeted European country
    active-threats
  6. 2026-06-22The Gentlemen — EDR-killer framework documented, OT-adjacent victim claimed, operator named
    weekly-multi-day
  7. 2026-06-22Energy, water & OT — perimeter and process failures, with an OT-adjacent halt
    weekly-sector-patterns
  8. 2026-06-22Check Point State of Ransomware Q1 2026 — ecosystem consolidation, with Switzerland and Germany named
    weekly-annual-reports
  9. 2026-06-20The Gentlemen (Storm-2697) claims OT-adjacent Mackay Sugar attack; operator attributed to a Russian national
    active-threats
  10. 2026-06-19ESET: the Gentlemen RaaS gang centrally builds and maintains its affiliates' EDR-killer framework
    research
  11. 2026-06-12The Gentlemen ransomware: 478 claimed leak-site victims, self-propagating Go encryptor, operator publicly named
    active-threats
  12. 2026-05-29The Gentlemen ransomware — Microsoft publishes full technical dissection of the Storm-2697 Go-encryptor
    active-threats
  13. 2026-05-25The Gentlemen / Storm-2697 — internal "Rocket" backend leaked by a rival; KELA and Check Point dissect the operator inner circle
    weekly-long-running
  14. 2026-05-25Check Point Q1 2026 State of Ransomware — ecosystem reconsolidates; LockBit returns with a deliberate Europe pivot
    weekly-annual-reports
  15. 2026-05-23Rapid7 Q1 2026 Threat Landscape Report: vulnerability exploitation now top initial-access vector at 38 %; KEV median time to listing collapses to 5 days
    research
  16. 2026-05-18The Gentlemen RaaS — Czech university and Swiss engineering firm listed; comms overhaul continues
    weekly-long-running
  17. 2026-05-14The Gentlemen RaaS — backend "Rocket" database leaked (16.22 GB), Check Point analysis exposes operator handles, ZeroPulse C2 internals, 1,570+ victims, decryptor published on GitHub
    active-threatsThe Gentlemen RaaS — backend "Rocket" database leaked (16.22 GB), Check Point analysis exposes operator handles, ZeroPulse C2 internals, 1,570+ victims
  18. 2026-05-11"The Gentlemen" RaaS — operations continue post-leak, decryptor published, FortiOS / Erlang SSH initial access CVEs confirmed
    weekly-long-running
  19. 2026-05-11Looking ahead — 2026-W20
    weekly-looking-ahead
  20. 2026-05-11Check Point April 2026 ransomware analysis — Qilin leads at 15%, Germany at 5% of global victims
    weekly-annual-reports
  21. 2026-05-04The Gentlemen RaaS — Europe-skewed operation surged approximately 448% QoQ; 32% of Q1 2026 victims in Europe; FortiGate CVE-2024-55591 initial-access funnel
    weekly-long-running
  22. 2026-05-04Looking ahead — 2026-W19
    weekly-looking-ahead
  23. 2026-05-04Akira playbook quarterly context — Q1 2026 healthcare concentration; Qilin remains the dominant operator on German healthcare victims
    weekly-long-running

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

overlaps with

documented in

attributed activity

Where this entity is cited

  • weekly-long-running7
  • active-threats5
  • weekly-annual-reports4
  • weekly-looking-ahead3
  • research2
  • weekly-sector-patterns1
  • weekly-multi-day1

Source distribution

  • attack.mitre.org5 (9%)
  • blog.checkpoint.com3 (5%)
  • research.checkpoint.com3 (5%)
  • bleepingcomputer.com2 (4%)
  • helpnetsecurity.com2 (4%)
  • huntress.com2 (4%)
  • almalinux.org1 (2%)
  • bankinfosecurity.com1 (2%)
  • other37 (66%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (56)

Entries about The Gentlemen (23)

2026-07-12 · view entry permalink →

NOTABLENATOB2

Looking ahead — 2026-W28

Items already in motion for the coming weeks — each with a dated source or an in-week entry, none a prediction:

  • EU regulatory clocks. The Dutch NIS2 Cyberbeveiligingswet enters into force 15 August 2026 — now a fixed date after the 7 July Senate passage (Rijksoverheid.nl, 2026-07-07). The EU Cyber Resilience Act vulnerability/incident-reporting obligation lands 11 September 2026, roughly 60 days out and previously covered in this store — the reporting-platform readiness is the item to watch next.
  • FINMA post-quantum guidance may harden. FINMA's Aufsichtsmitteilung 05/2026 is supervisory expectation-setting, not yet a binding circular; the open question is whether it converts into a Rundschreiben revision (FINMA, 2026-07-09).
  • Joomla file-upload wave — the newest members await exploitation. RSFiles! and Phoca Download are patched but not yet exploited, whereas earlier members of the same CWE-434 wave reached CISA KEV within days (mySites.guru, 2026-07-11) — treat these as likely-imminent-KEV, not resolved.
  • The Gentlemen EDR-disable zero-day. Unit 42 references an Expel analysis of a suspected zero-day the group uses to disable EDR, distinct from the GentleKiller BYOVD framework; that write-up had not published at the time of Unit 42's report (Unit 42, 2026-07-10).
  • CitrixBleed 2 broker activity continues. Huntress' STAC3725 reconstruction shows an initial-access broker actively weaponising CVE-2025-5777; organisations that patched but did not terminate live sessions remain exposed to token replay and downstream DragonForce deployment (Huntress, 2026-07-10).

Builds on: 2026-07-12/weekly-w28-netherlands-nis2-in-force · 2026-07-12/weekly-w28-finma-post-quantum-guidance · 2026-07-12/weekly-w28-joomla-file-upload-rce-wave · 2026-07-12/weekly-w28-the-gentlemen-status · 2026-07-12/weekly-w28-exploited-edge-enterprise-software · 2026-06-29/eu-cyber-resilience-act-75-days-to-the-11-september-vulnerab

outlook12 Jul 23:56Zmulti-sourceOpen finding ↗

2026-07-12 · view entry permalink →

NOTABLEupdateNATOB2

The Gentlemen (Storm-2697) status update — Unit 42's full profile: 580 victims, a Qilin-affiliate lineage, and a suspected EDR-disable zero-day

UPDATE · originally covered The Gentlemen (2026-06-29)

Palo Alto Unit 42 published the first full technical profile of The Gentlemen (Microsoft: Storm-2697; also Phantom Mantis), consolidating and extending the picture this pipeline built from ESET's GentleKiller research and the FortiBleed nexus. The delta worth carrying: Unit 42 counts 580 claimed victims across 77 countries through 3 July 2026 (103 in manufacturing) and a "slightly more than 6x" victim increase from H2 2025 to H1 2026, and assesses the ~20 operators "likely morphed from a private entity into a RaaS model on or about September 2025," previously operating as "ArmCorp," an affiliate of Qilin, now offering an "unprecedented 90% payout" versus the typical 70-80% (Unit 42, 2026-07-10). Two operationally relevant additions: the initial-access set now explicitly names Erlang/OTP SSH-server and Windows SMB-client flaws alongside the already-tracked FortiOS/FortiProxy edge path, and Unit 42 cites Expel describing a suspected zero-day the group uses specifically to disable target EDR agents — distinct from the BYOVD-based GentleKiller framework and not previously in this pipeline's coverage. The Go/C dual-language encryptor and Curve25519/XChaCha20 per-file key scheme are unchanged.

The operators (roughly 20 of them) likely morphed from a private entity into a RaaS model on or about September 2025. While traditional RaaS models typically offer affiliates a 70% to 80% cut of paid ransoms, The Gentlemen offer an unprecedented 90% payout.

When comparing the last six months of 2025 to the first six months of 2026, the number of victims claimed by The Gentlemen increased by slightly more than 6x.

Palo Alto Networks Unit 42
synthesis12 Jul 23:46Zsingle-sourceOpen finding ↗

2026-06-29 · view entry permalink →

HIGH

The Gentlemen

The W25 multi-day item now has primary-evidence depth (the ESET deep-dive, § 7) and a sharp Swiss angle: Check Point data, reported by Swiss tech press, makes Switzerland the second-most-targeted European country for the operation, which now claims 478 victims and has added worm propagation. The operationally important link is that victim selection runs on FortiGate misconfiguration scanning — so a Swiss organisation's FortiBleed exposure (above) is also its Gentlemen-victim-selection exposure. Outstanding for defenders: the same FortiGate hardening that closes FortiBleed reduces Gentlemen targeting, and EDR-tamper-protection plus driver-blocklist enforcement is the GentleKiller counter.

synthesis29 Jun 00:21Zmulti-sourceOpen finding ↗

Earlier coverage (20)

2026-06-29NOTABLEESET "Killing me gently" — a de-facto mid-year RaaS-tooling reportBackground. The Gentlemen emerged in late 2025 as a RaaS operation founded by "hastalamuerte" (a former Qilin affiliate per Group-IB, previously affiliated with Embargo, LockBit, Medusa and BlackLock per PRODAFT).2026-06-27HIGH"The Gentlemen" ransomware claims 478 victims and adds worm propagation — Switzerland the second-most-targeted European country"The Gentlemen" ransomware: Switzerland is the second-most-targeted European country (Check Point data via Swiss press), against a group profile of 478 claimed victims and an SMB --spread worm capability (inside-it.ch, 2026-06-26).2026-06-22NOTABLECheck Point State of Ransomware Q1 2026 — ecosystem consolidation, with Switzerland and Germany namedSurfaced this week for its CH/EU-specific findings, Check Point's Q1 2026 ransomware report (published 11 May, not covered in the dailies) documents a structural consolidation: the top 10 groups now hold 71.1% of all leak-site victims, the highest concentration since early 2024 and a reversal of two years of …2026-06-22NOTABLEEnergy, water & OT — perimeter and process failures, with an OT-adjacent haltCritical-infrastructure exposure ran from cyber intrusion to physical mishandling.2026-06-22HIGHThe Gentlemen — EDR-killer framework documented, OT-adjacent victim claimed, operator namedThe Gentlemen RaaS grew +315% in Q1 and impacted OT — ESET exposed its centrally-built GentleKiller EDR-killer; the gang halted milling at Mackay Sugar. (daily 06-19, ESET)2026-06-20NOTABLEThe Gentlemen (Storm-2697) claims OT-adjacent Mackay Sugar attack; operator attributed to a Russian nationalUPDATE (originally covered 2026-06-19): Following ESET's 2026-06-19 documentation of the group's GentleKiller EDR-killer framework, The Gentlemen ransomware group has claimed an OT-adjacent attack on Mackay Sugar (Australia's second-largest sugar producer), which confirmed on 2026-06-18 that an external party …2026-06-19NOTABLEESET: the Gentlemen RaaS gang centrally builds and maintains its affiliates' EDR-killer frameworkESET's months-long investigation into the Gentlemen ransomware-as-a-service operation reveals a structural departure from the affiliate norm: rather than each affiliate sourcing its own evasion tooling, the operators build, maintain and distribute a modular EDR-killing framework — GentleKiller — centrally (ESET …2026-06-12HIGHThe Gentlemen ransomware: 478 claimed leak-site victims, self-propagating Go encryptor, operator publicly namedThe Gentlemen RaaS claims 478 leak-site victims (concentrated in Thailand, the UK, Brazil, Germany and India per THN); Krebs publishes an operator deanonymisation, and Microsoft's dissection details the encryptor's --spread worm mode (KrebsOnSecurity, 2026-06-10).2026-05-29NOTABLEexploitedThe Gentlemen ransomware — Microsoft publishes full technical dissection of the Storm-2697 Go-encryptorUPDATE (originally covered 2026-05-20; consolidated in weekly W21): Microsoft Threat Intelligence published a full dissection of The Gentlemen ransomware on 2026-05-28, giving Storm-2697 a much sharper technical profile than the victim-list reporting available in week 21.2026-05-25HIGHThe Gentlemen / Storm-2697 — internal "Rocket" backend leaked by a rival; KELA and Check Point dissect the operator inner circleMost active RaaS exposed — The Gentlemen's internal database leaked. A rival dumped the operation's "Rocket" backend; KELA and Check Point analysis exposes the operator inner circle and an initial-access playbook (Fortinet/Cisco edges, NTLM relay, GPO deployment) that maps straight to hunts. (daily, Check Point)2026-05-25NOTABLECheck Point Q1 2026 State of Ransomware — ecosystem reconsolidates; LockBit returns with a deliberate Europe pivotHorizon research surfaced a quarterly report the dailies did not cover: Check Point's Q1 2026 State of Ransomware (published 2026-05-11).2026-05-23NOTABLERapid7 Q1 2026 Threat Landscape Report: vulnerability exploitation now top initial-access vector at 38 %; KEV median time to listing collapses to 5 daysRapid7 Labs published its Q1 2026 Threat Landscape Report on 2026-05-21 covering January–March 2026 IR data; the GlobeNewswire release accompanied the post the same day. The findings that change what a Swiss/EU public-sector SOC should prioritise:2026-05-18NOTABLEThe Gentlemen RaaS — Czech university and Swiss engineering firm listed; comms overhaul continuesThe Gentlemen RaaS listed two new European victims — the University of Finance and Administration (Czech Republic) and a Swiss engineering firm — on its leak site (daily 2026-05-20).2026-05-14HIGHThe Gentlemen RaaS — backend "Rocket" database leaked (16.22 GB), Check Point analysis exposes operator handles, ZeroPulse C2 internals, 1,570+ victims, decryptor published on GitHubThe Gentlemen RaaS backend dumped — Check Point exposes operator handles and tooling; SystemBC C&C reveals 1,570+ victims vs. 332 on the public leak site; decryptor on GitHub. Check Point Research's 2026-05-13 analysis of a 44.4 MB extract from the group's leaked "Rocket" backend (16.22 GB total, posted to the cybercrime forum Breached on 4 May after the group's infrastructure was compromised) maps nine operator handles, the EDR-suppression toolchain (EDRStartupHinder, gfreeze, glinker), the ZeroPulse C2 framework, and a separately-exposed SystemBC C&C server holding 1,570+ victim entries against 332 publicly listed in the first five months of 2026 — large under-reporting of true scope. The decryptor is public on GitHub per BankInfoSecurity, making decryption the first action for any in-flight Gentlemen incident (Check Point Research, 2026-05-13; BankInfoSecurity, 2026-05-11).2026-05-11NOTABLELooking ahead — 2026-W20Microsoft Exchange CVE-2026-42897 — Microsoft permanent patch and out-of-band advisory on DEVCORE Pwn2Own three-bug chain pending.2026-05-11NOTABLE"The Gentlemen" RaaS — operations continue post-leak, decryptor published, FortiOS / Erlang SSH initial access CVEs confirmedFollowing the 2026-05-04 Rocket backend DB leak (attributed to a breach of hosting provider 4VPS), administrator zeta88 / hastalamuerte announced a full communications-infrastructure overhaul — new NAS deployment and new locker upgrades — signalling no intent to cease operations.2026-05-11NOTABLECheck Point April 2026 ransomware analysis — Qilin leads at 15%, Germany at 5% of global victimsCheck Point's April 2026 monthly threat report (published early May 2026) confirms Qilin / Agenda leading all ransomware operators with 15% of 707 published attacks in April; Germany is the third-most-targeted country globally at 5.0% of victims (US 41.6%); Europe accounts for 27% of ransomware victims globally.2026-05-04NOTABLELooking ahead — 2026-W19Canvas / Instructure extortion deadline — Tuesday 2026-05-12 (two days out). Second-intrusion claim against Instructure made 2026-05-08 despite the May 8 patches; seven Dutch universities disconnected; Dutch DPA and ICO engaged.2026-05-04NOTABLEAkira playbook quarterly context — Q1 2026 healthcare concentration; Qilin remains the dominant operator on German healthcare victimsW1 horizon research added Q1 2026 healthcare quarterly context to the Groupe 3R item in § 1.2026-05-04NOTABLEexploitedThe Gentlemen RaaS — Europe-skewed operation surged approximately 448% QoQ; 32% of Q1 2026 victims in Europe; FortiGate CVE-2024-55591 initial-access funnelW1 horizon research identified an in-window operator gap the daily briefs missed.