Who Runs the Ransomware Group ‘The Gentlemen?’
A cybercrime group known as The Gentlemenhas emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group. A graphic created and shared by The Gentlemen ransomware group administrator Hastalamuerte on Breachforums in May 2026. Credit: ke-la.com. Experts at the security firm Check Point Softwarehave been closely covering exploits of The Gentlemen, a so-called “ransomware-as-a-service” (RaaS) offering that pays affiliates handsomely to help spread the group’s malware. “A 90/10 affiliate revenue split — compared to the industry standard 80/20 — is accelerating the group’s growth by attracting experienced operators from competing programs,” the researchers wrote in April. Check Point found The Gentlemen are the second most active ransomware group by victim count so far this year, claiming at least 332 published victims since the group’s inception in mid-2025 and more than 240 in 2026 alone. According to Check Point, the group targets Internet-facing devices (VPNs, firewalls) as their entry point, and once inside moves quickly to encrypt entire networks within hours. Check Point says the administrator and primary operator of the ransomware group uses the nickname Zeta88on the Russian-language cybercrime forums, and that this individual was previously known under the moniker Hastalamuerte. Check Point noted that a breach of the group’s backend infrastructure made it clear that Hastalamuerte/Zeta88 is the person who assembles the locker and RaaS panel, manages payments, and is essentially the administrator of the entire program who receives 10 percent of all ransoms. The cyber intelligence firm Intel 471shows that the user Hastalamuerte is a Russian and English speaking person who registered on almost a dozen cybercrime forums between 2019 and the present day, including Exploit, Breachforums, Ramp_V2, BHF, Raidforums, and Nulled. Intel 471 reveals that Hastalamuerte registered on Breachforums in January 2025 from an Internet address in Izhevsk, the capital city of Russia’s Udmurt Republic. Likewise, the user Zeta88signed up at the English-language cybercrime forum Breached in August 2022 from a different Internet address in Izhevsk. Intel 471 finds Hastalamuerte registered on Raidforums in 2020 using the email address [email protected] (1488 is a common combination of two numeric symbols associated with white supremacy). A lookup on this address at the open source intelligence service Epieosshows it is connected to an account at Apple and to a phone number ending in 04. Epieos says that Protonmail address is also linked to a GitHub account under the username SantaMuerte. That account is marked private, but a history of this user’s activity shows they are watching and developing a number of malware tools and exploits. In April 2020, Hastalamuerte said on the crime forum Nulled that they could be contacted at the Telegram instant messenger name @hastalamuerte18, and the threat intelligence company Flashpointfinds this username is assigned the unique Telegram ID number 30907522 [full disclosure: Flashpoint is an advertiser on this blog]. The breach tracking service Constella Intelligencereports that Hastalamuerte’s Telegram ID is connected to another username — “bu4vs” — and to the Russian phone number 79127650004. Pivoting on this phone number in Constella fetches multiple records from hacked Russian government databases showing it is assigned to one Alexander Andreevich Yapaev, a 36-year-old from Izhevsk. Constella reveals that phone number was used to create an account at the Russian social media platform Pikabu under the name “4apai18,” and shows Mr. Yapaev has signed up at a number of websites using the common surname Ivanov, or else “Chapaev” (the numeral 4 is often used as shorthand for a “ch” sound in Russian). A search in Intel 471 for cybercrime forum members with the nickname SantaMuerte unearths an account by the same name created in 2020 on the Russian hacking forum Codeby. Intel 471 shows this user originally registered on Codeby with the not-so-subtle nickname Alexandr 4apaev. Constella finds Mr. Yapaev regularly used the email address [email protected]. Meanwhile, Epieos shows this address is connected to a LinkedIn account for Alexander Yapaev, who lists himself as the head of B2B marketing at the company Uralenergo Udmurtia, one of Russia’s largest suppliers of electrotechnical and lighting products. Mr. Yapaev did not respond to multiple requests for comment. Nearly every time we publish one of these Breadcrumbs stories, readers are curious to know why it seems like so many cybercriminals from Russia apparently do little to hide their real life identities. The truth is that — Russian or not — most didn’t exactly set out to be arch criminals, but instead got drawn into the scene gradually over several years as their skills broadened and sharpened. Another important dynamic is that the Russian government generally either co-opts or ignores cybercriminal activity within its borders so long as the hackers do not steal from or attack Russian businesses and citizens. As a result, successful cybercriminals in Russia are usually insulated from prosecution and arrest by foreign law enforcement agencies provided they occasionally pay off the right people and do not travel abroad. And cybercriminals who intend to strictly adhere to those unwritten rules may (at least initially) be less concerned about covering their tracks online. But the simplest explanation is that cybercriminals of all nationalities tend to make a number of basic operational security mistakes early in their careers, when they are less savvy and have far less to lose by their carelessness. A review of Hastalamuerte’s early posts on the crime forums (circa 2019-2020) shows a relatively unsophisticated and low-skilled hacker still trying to learn the ropes and earn a positive reputation on these communities. For example, in June 2020 Hastalamuerte’s Telegram account joined a multi-month training program (@pntst) to learn how to use popular penetration testing tools, and their candid posts to this hacker training camp show Hastalamuerte struggling to use these tools effectively. A Google-translated record of Hastalmuerte’s posts to @pntst is here. Update, June 11, 10:23 a.m. ET: The threat research group PRODAFThas released a detailed writeup on the history and current operations of The Gentlemen. PRODAFT said its findings match the same persona with “high confidence,” and found the administrator (Zeta88/Hastalamuerte) supplies affiliates with initial access directly, primarily Fortinet SSL-VPN credentials obtained through brute-force attacks or sourced from the group’s own leak database. They also discovered the administrator is using AI to develop and maintain the ransomware and associated tooling, as well as to assist with post-exploitation activity.
WHO IS HASTALAMUERTE?
Related Articles
-
JIP to submit proposals seeking swift introduction of nuclear submarines
-
Jackery FridgeGuard Takes Stylish, Customer-Centric Design to Refrigerator Backup Battery
-
Magic's Marvel Super Heroes set gives an iconic spell a reprint with a catch
-
Save Over 60% Off the ThermoMaven X2 Wireless Meat Thermometer for Father's Day, Now Just $39.99
-
Honduras: Cedeño won’t disappear, it will relocate and persevere
-
Iran: Deadly drone strikes on Bahrain and Saudi Arabia may constitute war crimes – new research
- Latest Articles
-
- Nvidia Built Robots That Train Themselves Using AI Coding Agents
- Macron’s Nuclear Gamble: Building a European Deterrent Faster Than French Politics Can Tear Down
- Fired Rockstar developers can bring blacklisting claims against the GTA 6 developer, UK tribunal rules as final trial looms
- ‘We Just Want Clean Water’: Residents Sue a North Carolina County Over Landfill Contamination
- Why Trump is sabotaging his own nominee
- The ‘super El Niño’ is here. What happens next could upend food systems worldwide.
- Magic's Marvel Super Heroes set gives an iconic spell a reprint with a catch
- The world is built: Skyblivion devs call for extra quest-making hands to help overcome the massive mod's final roadblocks to release
- 'Scared to take him off' - Ronaldo struggles after fellow superstars sparkle
- Meow Wolf Puts Its Trippy Spin on ‘The Simpsons’ Opening Theme
- Random Reads
-
- You Can Save $15 On The Lego Star Wars Grogu & Hover Pram Set
- Magic's Marvel Super Heroes set gives an iconic spell a reprint with a catch
- The Dreame A3 AWD Pro Robot Lawn Mower Is The Perfect Gift for Father's Day
- DeBriefed 12 June 2026: El Niño begins | COP31 hosts eye electrification | Atlantic current monitoring at risk
- Vodafone outage RECAP: Users across Australia limited to SOS calls
- Analysis: UK’s EV drivers are now saving £1,100 each a year – and £3bn in total
- ‘We Just Want Clean Water’: Residents Sue a North Carolina County Over Landfill Contamination
- 10 best anime to watch with your girlfriend in 2026
- Middle East: Trump could restart Iran war if deal not signed
- Jackery FridgeGuard Takes Stylish, Customer-Centric Design to Refrigerator Backup Battery
- From its electric melee fights to its surprise Firewatch nods, Control Resonant's radical sequelcraft looks like it might just pay off
- Analysis: UK’s EV drivers are now saving £1,100 each a year – and £3bn in total
- A Colombian AI startup wants to assist half of Latin America’s doctors. Andreessen Horowitz just backed it.
- JetBlue Pushes Deeper Into Fort Lauderdale, Shrinks in Newark and LaGuardia
- Tunisia: Quash unjust convictions of anti-racism activists Saadia Mosbah and Mnemty staff
- Lebanon: Israel radically expands use of unlawful mass ‘evacuation’ orders and commits war crime of unlawful transfer
- What Color Is the Reflecting Pool? An Investigation.
- You Can Save $15 On The Lego Star Wars Grogu & Hover Pram Set
- Alabama Governor Names Four New PSC Members, Including Its First Two Black Appointees
- Toyota Rav4 Plug-in Hybrid vs. Tesla Model Y Basic
- Search
-
- Links
-
- Re: FCCPC and the Presidency’s FDI drive
- Prepare for the fear of the Ukrainian plumber
- Operating a Humanoid With Your Body Is a Hot Job in China’s Hardware Capital
- Ban mass movement of motorcycles
- Exclusive eBook: How AI is becoming the next military advisor
- VSCO launches Studio Pro mobile photo editing app and plans $500 per year subscription
- Barry Daly murder trial hears evidence of ‘serious trauma’ to right side of jaw
- Anthropic's design assistant now works better with its coding agent
- Work Visa in Panama: The Employer-Sponsored Route
- Tim Cook says Apple price increases are 'unavoidable' due to memory crunch