Tracing 'The Gentlemen' RaaS: OPSEC Trail Points to an Izhevsk Operator

A 90/10 affiliate split rocketed the crew to second place by victim count. The administrator's forum breadcrumbs are less impressive.

ThreatVectr Newsdesk· 3 min read
Tracing 'The Gentlemen' RaaS: OPSEC Trail Points to an Izhevsk Operator
Share

The ransomware-as-a-service crew tracked as The Gentlemen has moved from a mid-2025 newcomer to the second most prolific extortion brand by published victim count, according to telemetry from Check Point Research. The pitch to affiliates is simple: a 90/10 revenue split, well above the 80/20 most competing programs offer.

The math is working. More than 332 claimed victims since inception, with over 240 posted in 2026 alone.

Initial access tradecraft is unremarkable but effective — exposed VPN concentrators and edge firewalls, followed by rapid lateral movement and full-domain encryption inside hours. The TTPs overlap with several post-LockBit splinters, and I'd treat any cluster mapping as medium confidence until more incident response telemetry surfaces publicly.

The more interesting thread is attribution of the administrator.

Researchers say a breach of the group's backend tied the panel operator, locker builder, and payments handler to a single persona using Zeta88 on Russian-language forums, previously known as Hastalamuerte. Forum registration data from Intel 471 places Hastalamuerte across Exploit, Breachforums, Ramp_V2, BHF, Raidforums and Nulled, with sign-ups dating to 2019. Both Hastalamuerte and Zeta88 registered from IP space in Izhevsk, capital of Russia's Udmurt Republic.

The early OPSEC was rough.

Hastalamuerte registered on Raidforums in 2020 with hastalamuerte1488@protonmail.com — the 1488 suffix being a well-worn white supremacist numeric pairing. That ProtonMail address pivots through open-source enrichment to an Apple account, a phone number ending in 04, and a private GitHub under SantaMuerte whose watch history tracks malware and exploit repos.

A 2020 post on Nulled listed Telegram handle @hastalamuerte18, mapped to Telegram ID 30907522. Breach-data pivots on that ID surface a second handle, bu4vs, and the Russian mobile number 79127650004. That number appears in leaked Russian government records under the name Alexander Andreevich Yapaev, 36, of Izhevsk.

The same number registered a Pikabu account as 4apai18. On Codeby — a Russian-language hacking forum — a SantaMuerte account from 2020 originally registered under the handle Alexandr 4apaev. The bu4vs@mail.ru address attached to Yapaev resolves to a LinkedIn listing him as head of B2B marketing at Uralenergo Udmurtia, an electrotechnical supplier.

Yapaev did not respond to requests for comment.

None of this should surprise anyone who reads CTI for a living. Russian-based operators have long benefited from a tacit non-prosecution arrangement provided they avoid domestic targets and stay off foreign soil. That insulation tends to produce sloppy early-career OPSEC that never gets cleaned up later. Hastalamuerte's 2020 posts in a paid pentest training Telegram channel — @pntst — show an operator who at the time couldn't reliably drive Cobalt Strike or basic recon tooling.

Six years later, he allegedly runs the second-busiest ransomware brand on the board. Capability and trajectory are not the same thing.

© 2026 Threat Vectr