The Gentlemen RaaS: Origins, OPSEC & OSINT

Source: ctrlaltintel.com/research/… (Ctrl-Alt-Intel, 24 Jul 2026)

The Gentlemen ransomware-as-a-service operation rose rapidly in 2026, claiming nearly 500 victims by June and ranking second only to Qilin. The group originated as ArmCorp, a successful Qilin affiliate led by the handle hastalamuerte (also zeta88). After financial disputes with Qilin in mid-2025, the operators rebranded, first appearing publicly via a September 2025 forum advertisement that offered affiliates a 90 % revenue share and minimal infrastructure.

Persistent OPSEC failures—reused monikers, a long-lived residential Russian IP (92.39.211.142 in Izhevsk), Google Maps activity spanning 2017–2025, Rocket.Chat leaks, and forum breach data—allowed researchers to map the suspected leader’s infrastructure and travel across Russia, Dubai, China, Vietnam, and Thailand. Public reporting (including by Brian Krebs) later linked the persona to Alexander Andreevich Yapaev. The research highlights how relatively basic operational mistakes continue to expose even high-volume RaaS operators.

Edward Kiledjian @ekiledjian