top of page

"The Gentlemen" ransomware and the threat of double extortion tactics

1 day ago
2 min read

Recently, the cybersecurity situation in Hung Yen has faced complex developments as information systems of several local agencies and organizations showed signs of being compromised. The culprits behind these attacks have been identified as two dangerous ransomware strains named "The Gentlemen" and "Trigona." In response to the situation, the Hung Yen Provincial Police quickly issued an urgent warning to help units take timely preventive measures.

"Double extortion" tactics by ransomware of The Gentlemen

According to information from functional authorities, "The Gentlemen" is a cybercrime organization operating under the Ransomware-as-a-Service (RaaS) model and is sharply increasing its attack intensity in 2026.

To infiltrate victim systems, this group often targets Internet-connected devices with existing security vulnerabilities, such as Virtual Private Networks (VPNs) or firewall systems. Additionally, they leverage previously stolen administrative accounts to bypass security perimeters.

Once inside, The Gentlemen ransomware does not immediately lock data. Instead, they silently gather information, escalate privileges, disable antivirus software, and spread the malware across the entire system. Even more alarmingly, this ransomware strain employs "double extortion" tactics. They copy and exfiltrate all critical data before encrypting it. If victims refuse to pay the ransom to decrypt their files, the hackers threaten to leak this sensitive information online.

How to protect network systems?

To avoid becoming the next victim, the Hung Yen Provincial Police recommends that agencies and enterprises immediately review all servers and network devices. Particular attention should be paid to database management systems (such as MS SQL), VPN networks, virtualization servers, and remote connection protocols (RDP, SSH, SMB).

System administrators should not leave these communication ports wide open directly to the Internet. Instead, they should set access controls limiting allowed IP addresses and segment the network into separate zones for better control.

Concurrently, immediately applying security patches for software, operating systems, and firewall devices is an indispensable step—top priority should be given to vulnerabilities with global alerts. Organizations also need to establish a habit of regular data backups to always have contingency options when the primary system encounters an incident.

the-gentlemen-ransomware
Ransomware prevention methods (Source: Hung Yen Police)

Never compromise with hackers

In the event an incident occurs and a system shows signs of being attacked by The Gentlemen or Trigona, the immediate priority is to promptly disconnect (isolate) that device from the shared network. This helps prevent the malware from spreading to other computers while preserving the scene and access logs for investigation purposes.

The police agency particularly emphasizes: Victims must strictly refrain from contacting or paying ransoms to hackers on their own. Compromising with cybercriminals not only fails to guarantee data recovery but may also make the organization a recurring target for future attacks, extortion, or data leaks.

Instead of handling the situation independently, organizations should immediately report to and closely coordinate with the Police force and specialized information security bodies for timely technical support, investigation, and mitigation. Proactive prevention and continuous cybersecurity monitoring serve as the strongest shield to protect enterprises in the digital age.

Reference: Vietnamese Cybersecurity Magazine

follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
Logo-Zalo-Arc.webp
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
bottom of page