Marius Avram retweetledi

A leak has provided an unprecedented glimpse into the internal operations of the ransomware-as-a-service group known as "The Gentlemen". The group operated with a relatively small core team and recruited technical affiliates. Operators communicated via Tox protocol in addition to the Rocket.Chat. The primary initial access vector across all confirmed intrusions was CVE-2024-55591, a pre-authentication bypass in FortiOS/FortiProxy affecting HTTPS management interface and SSL-VPN. In some rare cases, the group obtained valid Okta credentials from commercial infostealer log markets, bypassing VPN/perimeter controls entirely. VERY cool report:
Tera@Tera0017
📄New CPr Publication: "Thus Spoke...The Gentlemen" Inside the leaked chats: 🔹 Internal workflow breakdown 🔹RaaS organization members 🔹Tools & CVEs 🔹Negotiation techniques A comprehensive look at how this group operates. Full report. 👇
English

























