A rapidly ascendant cybercrime syndicate known as "The Gentlemen" has rocketed to the position of the second most prolific ransomware gang based on victim count, a meteoric rise fueled by an aggressive recruitment strategy that dangles an unprecedented 90 percent share of ransom payments to its affiliates. This investigation delves into the digital breadcrumbs and intelligence unearthed by cybersecurity firms, pointing towards the real-life identity of the mastermind behind The Gentlemen ransomware operation.
Security experts at Check Point Software have been meticulously tracking the activities of The Gentlemen, a sophisticated ransomware-as-a-service (RaaS) operation that entices skilled hackers with exceptionally lucrative revenue splits. This generous 90/10 affiliate payout structure, a significant deviation from the industry standard 80/20, has proven instrumental in drawing experienced actors away from competing ransomware programs, thereby accelerating the group’s rapid expansion. Researchers from Check Point noted in April that The Gentlemen have emerged as the second most active ransomware entity this year, having publicly claimed responsibility for at least 332 victims since their inception in mid-2025, with a remarkable surge of over 240 victims recorded in 2026 alone.
The modus operandi of The Gentlemen typically involves targeting internet-facing devices, such as Virtual Private Networks (VPNs) and firewalls, as initial entry points into target networks. Once inside, the group demonstrates remarkable agility, moving swiftly to encrypt entire networks within a matter of hours.
According to insights provided by Check Point, the administrator and primary architect of The Gentlemen ransomware group operates under the pseudonym "Zeta88" on Russian-language cybercrime forums. Previously, this individual was known by the moniker "Hastalamuerte." Evidence, including a significant breach of the group’s backend infrastructure, has unequivocally established that Hastalamuerte/Zeta88 is the individual responsible for assembling the ransomware locker and the RaaS panel, managing all ransom payment processes, and ultimately serving as the central administrator of the entire operation, retaining the stipulated 10 percent commission from all ransoms collected.
Unmasking Hastalamuerte: A Digital Trail
The cyber intelligence firm Intel 471 has provided crucial insights into the user "Hastalamuerte," revealing a persona that is proficient in both Russian and English and has been actively participating in the cybercrime ecosystem since 2019. This individual has registered on a multitude of clandestine forums, including but not limited to Exploit, Breachforums, Ramp_V2, BHF, Raidforums, and Nulled, indicating a deep-seated engagement with the underground hacking community.
Intel 471’s research further pinpoints the geographical origins of Hastalamuerte, noting that the user registered on Breachforums in January 2025 from an Internet Protocol (IP) address originating in Izhevsk, the administrative center of Russia’s Udmurt Republic. Coincidentally, the user "Zeta88" also established an account on the English-language cybercrime forum Breached in August 2022, using a different IP address that also traces back to Izhevsk. This geographical correlation strongly suggests a shared origin for both personas.
A significant piece of the puzzle emerged when Intel 471 discovered Hastalamuerte’s registration on Raidforums in 2020. This registration was facilitated by the email address [email protected]. The inclusion of "1488" is particularly noteworthy, as it is a well-known combination of numeric symbols frequently associated with white supremacist ideologies. A further investigation of this email address using the open-source intelligence (OSINT) service Epieos revealed its connection to an Apple account and a phone number terminating in "04."
Epieos’s analysis also indicates that the aforementioned Protonmail address is linked to a GitHub account operating under the username "SantaMuerte." While this account is private, a historical review of the user’s activity, accessible through services like Gitspective, shows a consistent pattern of monitoring and developing various malware tools and exploits, signaling a technical proficiency and ongoing commitment to cyber offensive capabilities.
In April 2020, Hastalamuerte publicly declared on the crime forum Nulled that they could be contacted via Telegram using the username @hastalamuerte18. Threat intelligence company Flashpoint has identified this username as being assigned the unique Telegram ID number 30907522. It is important to note that Flashpoint is an advertiser on this blog.
Further corroboration comes from the breach tracking service Constella Intelligence, which reports that Hastalamuerte’s Telegram ID is associated with another username, "bu4vs," and the Russian phone number 79127650004. By cross-referencing this phone number within Constella’s extensive database, which includes compromised Russian government records, researchers found multiple entries linking it to one Alexander Andreevich Yapaev, a 36-year-old individual residing in Izhevsk.
Constella Intelligence’s findings extend to Yapaev’s online presence, revealing that this phone number was utilized to create an account on the Russian social media platform Pikabu under the username "4apai18." The investigation also uncovered a pattern of Mr. Yapaev signing up for various online services using the common Russian surname "Ivanov," or alternatively, "Chapaev." The numerical substitution of "4" for the "ch" sound is a recognized linguistic convention in Russian online communication.
A targeted search within Intel 471 for cybercrime forum members associated with the nickname "SantaMuerte" brought to light an account created in 2020 on the Russian hacking forum Codeby. Intel 471’s data indicates that this user initially registered on Codeby with the rather transparent nickname "Alexandr 4apaev," further strengthening the link to Alexander Yapaev.
Constella Intelligence also identified that Mr. Yapaev regularly used the email address [email protected]. This address, when cross-referenced with Epieos, connects to a LinkedIn profile for Alexander Yapaev. On his LinkedIn profile, Mr. Yapaev lists his occupation as the head of B2B marketing at Uralenergo Udmurtia, one of Russia’s largest suppliers of electrotechnical and lighting products. Mr. Yapaev did not respond to multiple requests for comment regarding these findings.
The persistent question of why many Russian cybercriminals appear to operate with such a degree of ostensible anonymity, or lack thereof, is multifaceted. It is often observed that individuals, regardless of nationality, do not typically embark on a criminal path with the explicit intention of becoming notorious figures. Instead, they are often gradually drawn into the cybercrime scene, with their skills evolving and sharpening over time.
A significant factor contributing to this phenomenon within Russia is the general tendency of the government to either co-opt or overlook cybercriminal activities conducted within its borders, provided these activities do not target Russian businesses or citizens. Consequently, successful cybercriminals in Russia often enjoy a degree of insulation from prosecution and arrest by international law enforcement agencies, contingent upon maintaining discretion and avoiding international travel. Cybercriminals who strictly adhere to these unwritten rules may, at least initially, feel less compelled to meticulously conceal their digital footprints.
However, a more straightforward explanation for the apparent lack of operational security among cybercriminals, across all nationalities, lies in the fundamental mistakes made early in their careers. During these formative stages, individuals are typically less experienced, less sophisticated, and have far less to lose from carelessness. A review of Hastalamuerte’s early forum posts, dating back to 2019-2020, reveals a hacker who was relatively unsophisticated and still in the process of learning the intricacies of the cybercrime world and building a reputation within these communities.
For instance, in June 2020, Hastalamuerte’s Telegram account joined a multi-month training program focused on penetration testing tools. Candid posts made by Hastalamuerte within this training environment indicate struggles with effectively utilizing these tools. A Google-translated record of these posts is available for review.
Update, June 11, 10:23 a.m. ET: The threat research group PRODAFT has released a comprehensive report detailing the history and current operations of The Gentlemen. PRODAFT’s findings corroborate the identification of the same persona with "high confidence." Their research indicates that the administrator (Zeta88/Hastalamuerte) directly provides affiliates with initial access, primarily leveraging Fortinet SSL-VPN credentials obtained through brute-force attacks or sourced from the group’s own data leak repositories. Furthermore, PRODAFT’s investigation uncovered that the administrator is employing artificial intelligence (AI) for the development and maintenance of the ransomware and its associated tooling, as well as to aid in post-exploitation activities.

