The Gentlemen Ransomware Expands With Rapid Affiliate Growth
2026-04-21T14:52:16Z•2a4046da03644b04dc1c9347682b0928734f79bba514d0819609bc939789fdda
CVE-2024-3721CVE-2026-33032DLL sideloadingFormbookGentlemenICSLazarus GroupMCP protocolMiraiNVD policy changeOT malwareRaaSSystemBCTBK DVRVercelZionSiphonadware (AV-killing)crypto-heistnation-statenginx-uiobfuscationransomwaresupply-chainthird-party-toolzero-day
What happened
Multiple high-impact cyber threats and trends reported: Gentlemen ransomware (RaaS) rapidly expanding with multi-platform attacks and SystemBC-linked infections; targeted attacks and supply‑chain/third‑party tool exploitation (notably a breach at Vercel); nation‑state crypto theft attributed to Lazarus (KelpDAO $290M); ZionSiphon OT malware targeting water infrastructure; Formbook using DLL sideloading and JS obfuscation; Mirai variant actively exploiting TBK DVR command‑injection (CVE-2024-3721); and a critical nginx-ui MCP authentication bypass (CVE-2026-33032) being actively exploited. Bró
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- 2a4046da03644b04dc1c9347682b0928734f79bba514d0819609bc939789fdda
- Enrichment time
- 2026-04-21T14:52:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.