The Gentlemen Ransomware Expands With Rapid Affiliate Growth

2026-04-21T14:52:16Z2a4046da03644b04dc1c9347682b0928734f79bba514d0819609bc939789fdda
CVE-2024-3721CVE-2026-33032DLL sideloadingFormbookGentlemenICSLazarus GroupMCP protocolMiraiNVD policy changeOT malwareRaaSSystemBCTBK DVRVercelZionSiphonadware (AV-killing)crypto-heistnation-statenginx-uiobfuscationransomwaresupply-chainthird-party-toolzero-day

What happened

Multiple high-impact cyber threats and trends reported: Gentlemen ransomware (RaaS) rapidly expanding with multi-platform attacks and SystemBC-linked infections; targeted attacks and supply‑chain/third‑party tool exploitation (notably a breach at Vercel); nation‑state crypto theft attributed to Lazarus (KelpDAO $290M); ZionSiphon OT malware targeting water infrastructure; Formbook using DLL sideloading and JS obfuscation; Mirai variant actively exploiting TBK DVR command‑injection (CVE-2024-3721); and a critical nginx-ui MCP authentication bypass (CVE-2026-33032) being actively exploited. Bró

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
2a4046da03644b04dc1c9347682b0928734f79bba514d0819609bc939789fdda
Enrichment time
2026-04-21T14:52:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · The Gentlemen Ransomware Expands With Rapid Affiliate Growth · Baitaphish