The Gentlemen Ransomware Operationalizes SystemBC SOCKS5 Botnet of 1,570+ Corporate Hosts for Double-Extortion Operations
The Gentlemen Ransomware Operationalizes SystemBC SOCKS5 (TL-2026-0399), also tracked as The Gentlemen RaaS, is a high-severity malware campaign scored CVSS 8.5, first published 2026-04-20. It is attributed to The Gentlemen (Russia) with medium confidence, affects Microsoft Windows, maps to 33 MITRE ATT&CK techniques (T1003, T1005, T1016), and is covered by 9 detection rules and 32 indicators of compromise.
Key facts for TL-2026-0399
- Threat ID
- TL-2026-0399
- Also known as
- The Gentlemen RaaS, Gentlemen-Locker, SystemBC Gentlemen Campaign
- Severity
- HIGH
- CVSS
- 8.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-04-20
- Last reviewed
- 2026-04-20
- Attribution
- The Gentlemen
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- manufacturing, logistics, legal, healthcare, financial, technology, professional-services, construction
- Target regions
- North America, Western Europe, Australia, United Kingdom
- Detection rules
- 9
- Indicators of compromise
- 32
Malware and tooling in The Gentlemen Ransomware Operationalizes SystemBC SOCKS5
Malware and tooling: Gentlemen-Locker, SystemBC - S9001, Cobalt Strike, Rclone - S1040, SystemBC Panel v3.3.2
The Gentlemen ransomware group has weaponized the SystemBC proxy malware botnet — commanding more than 1,570 compromised corporate hosts as a distributed SOCKS5 anonymization layer for ransomware intrusions. The fusion of a mature loader/proxy family (SystemBC) with an active double-extortion RaaS operation collapses C2 traffic into trusted enterprise IP space, defeats geolocation and reputation controls, and provides ransomware affiliates with a low-cost, high-resilience staging network for reconnaissance, data theft, and payload delivery.
How The Gentlemen Ransomware Operationalizes SystemBC SOCKS5 works
The Gentlemen is a ransomware-as-a-service (RaaS) operation that surfaced in late 2025 with double-extortion attacks against manufacturing, logistics, legal, and healthcare verticals across North America and Western Europe. Independent research published in April 2026 by BleepingComputer and Lumen's Black Lotus Labs documents the group's operational integration with SystemBC — a malware family first sold on Russian-speaking underground forums in 2018–2019 as a generic SOCKS5 proxy and loader. Historically, SystemBC was bundled with Conti, Ryuk, Royal, Hive, and Egregor intrusions as a tertiary C2 relay; the 2026 campaign represents the first publicly disclosed fusion in which the proxy botnet itself is treated as primary operational infrastructure for a single ransomware brand.
Black Lotus Labs' April 2026 telemetry identifies a persistent backbone of more than 1,570 simultaneously-active SystemBC nodes, the vast majority of which are compromised corporate hosts (Windows servers, workstations, and Linux systems running legacy web applications). Affiliates of The Gentlemen route reconnaissance scans, Cobalt Strike beacons, Rclone exfiltration, and ransomware payload stagers through these nodes, causing malicious traffic to originate from the trusted ASN ranges of victim peers. The botnet is tiered: an outer ring of short-lived residential proxies absorbs scanning and credential-testing traffic, while a long-lived inner ring of compromised corporate hosts is reserved for hands-on-keyboard intrusions.
Initial access vectors observed in The Gentlemen intrusions include opportunistic exploitation of unpatched perimeter appliances (Fortinet FortiOS, Ivanti Connect Secure, Citrix NetScaler), phishing delivery of SocGholish and GootLoader frameworks that drop SystemBC as second-stage, and purchase of network access from initial access brokers. Once footholds are established, operators deploy a customized SystemBC variant (internal version string 3.3.2) that communicates with a hard-coded C2 list over a proprietary binary protocol on TCP ports 4001, 4044, and 4444, and establishes SOCKS5 listeners that the ransomware tooling proxies through. Post-compromise tooling includes Cobalt Strike 4.9, Sliver, Impacket's secretsdump.py, Mimikatz, AnyDesk/ScreenConnect for persistence, and Rclone for data staging to Mega.nz and BackBlaze B2 buckets before the ransomware payload executes.
The ransomware payload itself is a Go-based encryptor branded as 'Gentlemen-Locker' that uses ChaCha20 for file encryption with per-file keys protected by an X25519 hybrid scheme, appends the extension `.gntlm`, and drops a ransom note (`HOW-TO-DECRYPT-GENTLEMEN.txt`) containing a victim-unique Tor .onion negotiation portal. Leak-site data from the group's Tor dark-web portal confirms at least 47 named victims between December 2025 and April 2026, with initial ransom demands ranging from USD 480,000 to USD 9.2 million. The fusion of botnet proxy infrastructure with the ransomware brand dramatically reduces affiliate operating costs: Lumen estimates that the SystemBC backbone saves affiliates approximately USD 200 per hour in residential-proxy rental fees while providing significantly higher trust scores for egress traffic.
Defenders should treat any host beaconing to the SystemBC IOC list as a pre-ransomware indicator and trigger containment playbooks rather than routine cleanup. Network detection should focus on the distinctive SystemBC protocol handshake (little-endian length-prefixed binary frames, sub-200-byte initial registration), anomalous outbound SOCKS5 listeners on corporate assets, and process-genealogy signatures where RunDLL32, WerFault, or svchost spawn children communicating to high ports on sparse-reputation IPs. EDR should alert on the combination of Rclone execution, LSASS access by non-SYSTEM processes, and Volume Shadow Copy deletion within a 30-minute window.
MITRE ATT&CK techniques used in TL-2026-0399
Credential Access
T1003 OS Credential Dumping; T1555 Credentials from Password Stores
Collection
T1005 Data from Local System; T1560 Archive Collected Data
Discovery
T1016 System Network Configuration Discovery; T1018 Remote System Discovery; T1482 Domain Trust Discovery
Lateral Movement
T1021 Remote Services; T1570 Lateral Tool Transfer
Defense Evasion
T1027 Obfuscated Files or Information; T1070 Indicator Removal; T1218 System Binary Proxy Execution
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Persistence
T1053 Scheduled Task/Job; T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution
Privilege Escalation
T1055 Process Injection; T1548 Abuse Elevation Control Mechanism
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution; T1569 System Services
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1095 Non-Application Layer Protocol; T1105 Ingress Tool Transfer
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1566 Phishing
Impact
T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery
defense-impairment
Affected products and versions in The Gentlemen Ransomware Operationalizes SystemBC SOCKS5
- Microsoft — Windows
Vulnerable versions: Windows 10; Windows 11; Windows Server 2016; Windows Server 2019; Windows Server 2022 - Linux — Linux distributions (any glibc-based)
Vulnerable versions: RHEL 7/8/9; Ubuntu 18.04/20.04/22.04; Debian 10/11/12; CentOS 7 - Fortinet — FortiOS / FortiGate (initial access vector)
Vulnerable versions: 7.0.x <7.0.14; 7.2.x <7.2.7; 7.4.x <7.4.5
Fixed in: 7.0.14; 7.2.7; 7.4.5 - Ivanti — Connect Secure / Policy Secure (initial access vector)
Vulnerable versions: <22.7R2.6
Fixed in: 22.7R2.6 - Citrix — NetScaler ADC / Gateway (initial access vector)
Vulnerable versions: <14.1-29.72; <13.1-55.34
Fixed in: 14.1-29.72; 13.1-55.34
Remediation for The Gentlemen Ransomware Operationalizes SystemBC SOCKS5
Patches
- Ensure all perimeter SSL-VPN and edge appliances are patched to vendor-current versions (FortiOS 7.4.5+, Ivanti Connect Secure 22.7R2.6+, Citrix NetScaler 14.1-29.72+).
- Patch Windows endpoints for LSASS protection (Credential Guard, RunAsPPL), and enable ASR rule 'Block credential stealing from LSASS' (9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2).
- Ensure antivirus/NGAV signatures are current: SystemBC 3.x is detected by major vendors as Backdoor:Win32/SystemBC, Trojan.SystemBC, or Proxy.SystemBC.
Immediate actions
- Block all SystemBC C2 IPs and domains in this report at perimeter firewalls, cloud egress gateways, and DNS resolvers (RPZ).
- Hunt for outbound TCP connections to high ports (4001, 4044, 4444) from non-developer workstations and servers — isolate matching hosts.
- Search EDR for process genealogy: rundll32.exe or regsvr32.exe spawning children that establish external SOCKS5 listeners or connect to flagged IOC ranges.
- Force credential rotation for any account that logged into a host observed beaconing to SystemBC infrastructure within the last 90 days.
- Disable outbound traffic on ports 4001, 4044, and 4444 enterprise-wide unless explicitly documented business justification exists.
- Query recent proxy / NetFlow logs for the SystemBC binary handshake pattern (short length-prefixed registration packet followed by bidirectional encrypted tunnel).
Workarounds
- Where patching edge appliances is not immediately possible, restrict management interfaces to trusted admin IPs only and disable unused web UIs.
- Temporarily disable SOCKS5-capable applications (e.g., Proxifier, FoxyProxy) across managed endpoints via application control policies.
- Enforce outbound firewall deny-by-default for endpoints that do not require direct internet egress (server VLANs, OT/ICS, finance workstations).
Longer-term hardening
- Deploy EDR with behavioral detection for proxy-chaining, anomalous outbound tunnels, and SOCKS5 listeners bound on corporate endpoints.
- Implement egress filtering with allow-lists for server tiers; restrict workstation egress to a web proxy with TLS inspection where policy permits.
- Segment corporate networks so compromised user workstations cannot host inbound connections from external IPs (default-deny inbound at host firewall).
- Enable immutable, offline, and offsite backups with tested restore procedures; confirm backup repositories are isolated from domain authentication.
- Deploy canary files and honeytokens in file shares; alert on any touch, especially by service accounts or after-hours sessions.
- Standardize disabling of Volume Shadow Copy deletion via domain GPO and alert on `vssadmin delete shadows` and `wbadmin delete catalog` invocations.
- Harden perimeter appliances (FortiOS, Ivanti Connect Secure, Citrix NetScaler): patch monthly, enable MFA, monitor admin panel auth, rotate keys quarterly.
Weaknesses (CWE) in The Gentlemen Ransomware Operationalizes SystemBC SOCKS5
CWE-506, CWE-912, CWE-693, CWE-285, CWE-799
Timeline of The Gentlemen Ransomware Operationalizes SystemBC SOCKS5
- SystemBC SOCKS5 proxy/loader malware first advertised on Russian-speaking underground forums as commodity anonymization service.
- Proofpoint publishes foundational research 'SystemBC is Christmas in July,' documenting distribution via Fallout and RIG exploit kits.
- Sophos publishes first broad analysis linking SystemBC to Ryuk, Conti, and Egregor ransomware intrusions as a common post-exploitation component.
- CISA advisory AA21-265A on Conti ransomware explicitly names SystemBC as observed in affiliate toolkits.
- First confirmed victim posted to The Gentlemen's Tor leak site (a North American logistics firm).
- The Gentlemen advertised as affiliate-only RaaS program on RAMP and XSS forums; affiliates receive 80% revenue split.
- Updated SystemBC variant (internal version 3.3.2) observed using TCP 4044 and 4444 in addition to historical 4001, with added traffic obfuscation layer.
- Two large European manufacturers hit within 72 hours; both showed SystemBC beacons from domain controllers weeks prior to encryption event.
- Black Lotus Labs (Lumen) publishes telemetry showing 1,570+ simultaneously active SystemBC nodes serving as proxy backbone for The Gentlemen.
- BleepingComputer amplifies the research, attributing the SystemBC backbone primarily to The Gentlemen RaaS affiliate operations.
- Threadlinqs Intelligence publishes TL-2026-0399 with full IOC set, MITRE mapping, and multi-platform detection coverage.
- As of 2026-05-29, The Gentlemen RaaS and its SystemBC SOCKS5 botnet remain a live, escalating threat — ~332 published victims in the first five months of 2026 make it the second-most prolific ransomware op, corroborated by Check Point, Group-IB and The Hacker News. A May 4 backend leak (via 4VPS) did not stop them; the admin announced infra/locker upgrades and continued operating under the same brand with no takedown or arrests.
Sources cited for The Gentlemen Ransomware Operationalizes SystemBC SOCKS5
- The Gentlemen Ransomware Leverages SystemBC Proxy Botnet of 1,570+ Corporate Hosts
- SystemBC RAT Proxy Infrastructure Analysis
- Proofpoint — SystemBC is Christmas in July: SOCKS5 Malware and Exploit Kits
- Sophos — SystemBC malware used in ransomware attacks
- CISA — #StopRansomware: Conti Ransomware (historical SystemBC usage)
- MITRE ATT&CK — Software: SystemBC (S0603)
- Trellix — SystemBC Anonymization and SOCKS5 Proxy
- Recorded Future — SystemBC as Service for Ransomware Operators
Threats related to The Gentlemen Ransomware Operationalizes SystemBC SOCKS5
- The Gentlemen RaaS (Storm-2697) — Multi-Platform Ransomware-as-a-Service with BYOVD Defense Evasion and Self-Propagating Go Encryptor
- LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)
- Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and Kontron Driver BYOVD for Access and Privilege Escalation
- Payload Ransomware Targeting Windows and VMware ESXi with Babuk-Derived Curve25519/ChaCha20 Encryption
- Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
- CitrixBleed 2 (CVE-2025-5777) Weaponized by Initial Access Broker for DragonForce Ransomware Deployment
Detection coverage for TL-2026-0399
As of 2026-04-20, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0399 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.