ADVERTISEMENT

Exposed ransomware server reveals automated $4 cyberattacks

Irreversible changes in cybercrime: just $4 in tokens is the cost of compromising a company, exfiltrating data, and demanding millions in ransom.

massive ransomware operation run by an affiliate of The Gentlemen

Massive ransomware operation run by an affiliate of The Gentlemen. Image by Cybernews.

Ernestas Naprys
Ernestas Naprys Senior Journalist
September 2, 2026 Updated: 10 minutes ago 6 min read
Key takeaways:
the gentlemen 1
A scan of the exposed directory. Image by Cybernews.

What did we find on the server?

the gentlemen 3
The Gentlemen recruitment post lures new affiliates with revenue splits well above industry average. Image by Cybernews.
  • Penelope MCP (Model Context Protocol) interface – a connector for AI agents to interact with the reverse shell.
  • A beacon for deploying malicious payloads on compromised hosts.
  • Upload web server – a “drop box” for receiving data (HTTP PUT) from victim servers.
  • Three active penelope reverse shells.
  • Hermes harness.
  • Open web directory.
the gentlemen 2
A ransom note found on the exposed web directory. Image by Cybernews.

AI does all the work for just $4 in token charges

the gentlemen 7
The initial prompt reveals that the AI agent runs for a fraction of a dollar. Image by Cybernews.

A deeper look: How do criminals jailbreak AI?

ADVERTISEMENT
the gentlemen 6
AI-generated data exfiltration plan. Image by Cybernews.
  • Use open-source tools for configuration analysis (SAST).
  • Use open-source tools for secret scanning.
  • Use open-source tools for API enumeration.
  • Use open-source tools for secret extraction.
  • Use Penelope shells for interacting with target runners and pivot hosts.
  • Use an open-source post-exploitation C2.
the gentlemen 4
An AI agent evaluates the monetization prospects of the stolen data. Image by Cybernews.
the gentlemen 9
AI plans exploitation and generates a priority report. Image by Cybernews.
  • Direct extortion, demanding ransom from the original victim.
  • Offering data to business competitors – source code and private data are offered separately.
  • Auctioning data on the dark web.
  • Conducting phishing and SMS fraud campaigns themselves.
the gentlemen 8
Ransom amount calculation. Image by Cybernews.
the gentlemen 11
AI-generated “pressure dossier” for ransomware negotiations. Image by Cybernews.

Opportunistic attacks can hit any company

gentlemen-ransomware
Image by Cybernews.

How to protect yourself from similar threats?

Check if your data has been leaked

Find out if your email, phone number or related personal information might have fallen into the wrong hands.
18,611,353,922
Breached accounts
36,030
Breached websites
  • CVE-2021-22205 (remote code execution).
  • CVE-2023-7028 (account takeover).
  • CVE-2023-2825 (path traversal).
  • CVE-2021-22214 (server-side request forgery).
Ernestas Naprys
Senior Journalist
ADVERTISEMENT