HomeSecurityGentlemen’s RaaS: New Platform Advertised on Hacking Forums

Gentlemen's RaaS: New Platform Advertised on Hacking Forums

A new ransomware-as-a-service platform called Gentlemen's RaaS has recently appeared on underground hacking forums, offering malicious users a sophisticated cross-platform.

Gentlemen's RaaS

The service, promoted by malicious user zeta88, represents a significant expansion in ransomware distribution models, targeting critical infrastructure across multiple operating systems. This development signals an intensified threat landscape, where organized cybercriminals are offering “partner-based ransomware operations” to lower-level attackers, facilitating access to encryption malware.

See also: Phishing: Distribution of PureHVNC RAT via court documents

The service leverages an attractive business model that distributes 90% of ransomware revenue to partners, while retaining only 10% for the administrator. This generous revenue sharing structure has proven to be particularly attractive to potential partners within the cybercriminal ecosystem. By offering these financial incentives, the platform encourages widespread adoption and rapid growth across global organizations.

The architecture reflects a deliberate strategy to scale ransomware operations efficiently, while maintaining operational control through a centralized decryption infrastructure.

Gentlemen's RaaS: New Platform Advertised on Hacking Forums

KrakenLabs researchers identified the malware after a detailed analysis of promotional materials circulating on hacking forums.

The platform features sophisticated technical construction with separate lockers designed for specific platforms.

See also: Gunra ransomware attacks Windows and Linux

Gentlemen's RaaS: Lateral movement

The most notable technical elements include the malware's persistence and lateral movement mechanisms

Gentlemen's RaaS is developing a Go-based locker targeting Windows, Linux, NAS, and BSD, while using a separate C-coded ESXi locker, about 32 kilobytes in size. The encryption is implemented using XChaCha20 in combination with Curve25519 cryptography and per-file temporary keys.

Particularly concerning is the ability to self-propagate via WMI, WMIC, SCHTASKS, SC, and PowerShell Remoting commands, allowing rapid network traversal.

See also: GhostCall & GhostHire: BlueNoroff's new campaigns

Gentlemen's RaaS: New Platform Advertised on Hacking Forums

The malware establishes persistence via schtasks registry modifications and run-on-boot routines, ensuring survival across system reboots and administrative interventions. Additionally, the platform supports shared network discovery and automatic encryption, allowing the ransomware to locate and compromise adjacent systems without any problems.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS