home.social

#chacha20 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #chacha20, aggregated by home.social.

  1. ‘The Gentlemen’ Profile: Why This Ransomware Group Wants In Before It Locks You Out

    The Gentlemen is a financially motivated ransomware group operating since July 2025 using a Ransomware-as-a-Service model with dual-extortion tactics. They exfiltrate sensitive data before encrypting systems, targeting Windows, Linux, and ESXi environments. The group focuses heavily on preparation before encryption, using legitimate administrative tools like PowerRun.exe for privilege escalation, and establishing persistence through multiple mechanisms including registry modifications, scheduled tasks, and autostart configurations. They disable security tools, delete logs, terminate database and backup services, and use XChaCha20 and Curve25519 encryption. Primarily targeting medium-to-large organizations in the Asia-Pacific region, their activity has increased by 2,100% compared to typical levels. Victims receive ransom notes with approximately 10-day deadlines threatening to publish stolen data on leak sites if demands are not met.

    Pulse ID: 6a9035ff9a03d932d9008b31
    Pulse Link: otx.alienvault.com/pulse/6a903
    Pulse Author: AlienVault
    Created: 2026-08-27 13:05:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #0Day #Asia #ChaCha20 #CyberSecurity #Encryption #Extortion #ICS #InfoSec #Linux #OTX #OpenThreatExchange #RAT #RansomWare #RansomwareAsAService #SMS #Windows #bot #AlienVault