The Gentlemen Ransomware Operationalizes SystemBC SOCKS5 Botnet of 1,570+ Corporate Hosts for Double-Extortion Operations — Threadlinqs Intelligence
As of 2026-05-30, The Gentlemen Ransomware Operationalizes SystemBC SOCKS5 Botnet of 1,570+ Corporate Hosts for Double-Extortion Operations is a high-severity malware threat attributed to The Gentlemen (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 32 indicators of compromise.
Threat ID: TL-2026-0399 · Severity: HIGH · CVSS: 8.5 · Status: ACTIVE · Category: MALWARE
Attribution: The Gentlemen · Russia · FINANCIAL
The Gentlemen ransomware group has weaponized the SystemBC proxy malware botnet — commanding more than 1,570 compromised corporate hosts as a distributed SOCKS5 anonymization layer for ransomware
The Gentlemen is a ransomware-as-a-service (RaaS) operation that surfaced in late 2025 with double-extortion attacks against manufacturing, logistics, legal, and healthcare verticals across North America and Western Europe. Independent research published in April 2026 by BleepingComputer and Lumen's Black Lotus Labs documents the group's operational integration with SystemBC — a malware family first sold on Russian-speaking underground forums in 2018–2019 as a generic SOCKS5 proxy and loader. Historically, SystemBC was bundled with Conti, Ryuk, Royal, Hive, and Egregor intrusions as a tertiary C2 relay; the 2026 campaign represents the first publicly disclosed fusion in which the proxy botnet itself is treated as primary operational infrastructure for a single ransomware brand.
Black Lotus Labs' April 2026 telemetry identifies a persistent backbone of more than 1,570 simultaneously-active SystemBC nodes, the vast majority of which are compromised corporate hosts (Windows servers, workstations, and Linux systems running legacy web applications). Affiliates of The Gentlemen route reconnaissance scans, Cobalt Strike beacons, Rclone exfiltration, and ransomware payload stagers through these nodes, causing malicious traffic to originate from the trusted ASN ranges of victim peers. The botnet is tiered: an outer ring of short-lived residential proxies absorbs scanning and credential-testing traffic, while a long-lived inner ring of compromised corporate hosts is reserved for hands-on-keyboard intrusions.
Initial access vectors observed in The Gentlemen intrusions include opportunistic exploitation of unpatched perimeter appliances (Fortinet FortiOS, Ivanti Connect Secure, Citrix NetScaler), phishing delivery of SocGholish and GootLoader frameworks that drop SystemBC as second-stage, and purchase of network access from initial access brokers. Once footholds are established, operators deploy a customized SystemBC variant (internal version string 3.3.2) that communicates with a hard-coded C2 list over a proprietary binary protocol on TCP ports 4001, 4044, and 4444, and establishes SOCKS5 listeners that the ransomware tooling proxies through. Post-compromise tooling includes Cobalt Strike 4.9, Sliver, Impacket's secretsdump.py, Mimikatz, AnyDesk/ScreenConnect for persistence, and Rclone for data staging to Mega.nz and BackBlaze B2 buckets before the ransomware payload executes.
The ransomware payload itself is a Go-based encryptor branded as 'Gentlemen-Locker' that uses ChaCha20 for file encryption with per-file keys protected by an X25519 hybrid scheme, appends the extension `.gntlm`, and drops a ransom note (`HOW-TO-DECRYPT-GENTLEMEN.txt`) containing a victim-unique Tor .onion negotiation portal. Leak-site data from the group's Tor dark-web portal confirms at least 47 named victims between December 2025 and April 2026, with initial ransom demands ranging from USD 480,000 to USD 9.2 million. The fusion of botnet proxy infrastructure with the ransomware brand dramatically reduces affiliate operating costs: Lumen estimates that the SystemBC backbone saves affiliates approximately USD 200 per hour in residential-proxy rental fees while providing significantly higher trust scores for egress traffic.
Defenders should treat any host beaconing to the SystemBC IOC list as a pre-ransomware indicator and trigger containment playbooks rather than routine cleanup. Network detection should focus on the distinctive SystemBC protocol handshake (little-endian length-prefixed binary frames, sub-200-byte initial registration), anomalous outbound SOCKS5 listeners on corporate assets, and process-genealogy signatures where RunDLL32, WerFault, or svchost spawn children communicating to high ports on sparse-reputation IPs. EDR should alert on the combination of Rclone execution, LSASS access by non-SYSTEM processes, and Volume Shadow Copy deletion within a 30-minute window.
Weaknesses (CWE)
CWE-506, CWE-912, CWE-693, CWE-285, CWE-799
Target sectors: manufacturing, logistics, legal, healthcare, financial, technology, professional-services, construction
Target regions: North America, Western Europe, Australia, United Kingdom
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 32 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1190, T1566, T1078, T1059, T1204, T1569, T1547, T1053, T1543, T1055