Executive Overview
In the highly competitive cybercrime ecosystem, a ransomware-as-a-service (RaaS) syndicate known as The Gentlemen has staged a dramatic rise to become the second most active ransomware operation globally by victim count. Launched in mid-2025, the group’s meteoric growth—claiming at least 332 published victims, including more than 240 in 2026 alone—has been fueled by a disruptive, aggressive recruitment strategy designed to cannibalize talent from rival threat groups.
By offering criminal affiliates an unprecedented 90/10 revenue split—a sharp contrast to the established 80/20 industry standard—The Gentlemen has successfully lured experienced operators away from competing cybercrime syndicates. These affiliates target Internet-facing infrastructure, such as virtual private networks (VPNs) and firewalls, rapidly moving from initial access to full-network encryption within mere hours.
Behind this sophisticated operation lies an administrator known in the criminal underground by the monikers Zeta88 and Hastalamuerte. Recent backend infrastructure leaks and open-source intelligence (OSINT) investigations have pulled back the curtain on this key figure. Digital breadcrumbs left across public forums, compromised state databases, and social media networks tie Zeta88/Hastalamuerte directly to a real-world identity: Alexander Andreevich Yapaev, a 36-year-old corporate marketing executive based in Izhevsk, Russia.
Detailed Chronology of an Unmasking
The transformation of an aspiring cyber enthusiast into the administrator of a major ransomware cartel unfolded over several years, marked by a paper trail of operational security (OPSEC) blunders that ultimately compromised his real-world identity.
[2019 - 2020]
Early Cybercrime Registrations
Monikers: Hastalamuerte, SantaMuerte, Alexandr 4apaev
Platforms: Raidforums, Nulled, Codeby
Activities: Struggling with basic penetration testing tools (@pntst camp); setting up initial online identities.
[April - June 2020]
Technical Skill Building & Contact Footprints
Contacts shared: Telegram @hastalamuerte18 (ID: 30907522), ProtonMail ([email protected])
Identities linked: GitHub "SantaMuerte" developing malware utilities.
[August 2022 - January 2025]
Expansion Across Crime Underground
Monikers: Zeta88, Hastalamuerte
Platforms: Breached, Breachforums, Exploit, Ramp_V2, BHF
Geographic Footprint: Registrations logged from IP addresses in Izhevsk, Russia.
[Mid-2025 - 2026]
Launch of 'The Gentlemen' RaaS
Role: Program Administrator (Zeta88 / Hastalamuerte)
Functions: Assembling lockers/panel, managing 90/10 payouts, deploying AI tooling, orchestrating 332+ ransom attacks.
The Early Years (2019–2020)
Between 2019 and 2020, the individual operating as Hastalamuerte began establishing a digital presence across multiple cybercrime platforms, including Nulled, Raidforums, and the Russian hacking forum Codeby. Early forum activity reveals a novice operator struggling to acquire fundamental technical capabilities.
In June 2020, Hastalamuerte’s Telegram account joined @pntst, a multi-month online training program focused on teaching users how to deploy penetration testing software. Candid logs from the training camp demonstrate that the user frequently struggled to execute basic tools and commands, exposing a low level of technical sophistication during the initial stages of his cybercrime career.
Around this time, the user registered on Codeby under the handle Alexandr 4apaev before transitioning to SantaMuerte. On Raidforums, the user registered using the email address [email protected]. In April 2020, Hastalamuerte invited contacts on Nulled to reach him on Telegram via the handle @hastalamuerte18.
Underground Expansion and Platform Setup (2022–2025)
As the operator’s skill set expanded, so did his activity across illicit marketplaces. He registered on high-profile forums including Exploit, Breachforums, Ramp_V2, BHF, and Breached.
In August 2022, the user alias Zeta88 registered on the English-language crime forum Breached from an Internet Protocol (IP) address located in Izhevsk, the capital city of Russia’s Udmurt Republic. In January 2025, the moniker Hastalamuerte registered on Breachforums from a secondary IP address within the same geographic location of Izhevsk.
The Rise of ‘The Gentlemen’ (Mid-2025–2026)
In mid-2025, Zeta88/Hastalamuerte launched The Gentlemen as a ransomware-as-a-service model. Acting as the core administrator, he took charge of assembling the ransomware locker, building the affiliate management panel, orchestrating ransom payments, and retaining a 10 percent administrative cut from every successful extortion attempt.
By mid-2026, a major breach of the group’s backend infrastructure exposed operational chats and technical logs. Threat intelligence researchers analyzed these internal communications, definitively proving that Zeta88 and Hastalamuerte were the same individual directing the administrative apparatus of The Gentlemen.
Forensic Pivot Breakdown
The identification of Alexander Andreevich Yapaev resulted from a chain of interconnected digital pivots uncovered by cybersecurity firms, including Intel 471, Constella Intelligence, Flashpoint, Epieos, and Check Point Software.
+-------------------------------------------------------------+
| Raidforums / Nulled Registration |
| Moniker: Hastalamuerte | Telegram: @hastalamuerte18 |
+-------------------------------------------------------------+
|
v
+-------------------------------------------------------------+
| Digital Footprint Pivot |
| Email: [email protected] | Telegram ID: 30907522 |
+-------------------------------------------------------------+
|
v
+-------------------------------------------------------------+
| Data Breach Cross-Match |
| Phone Number: +79127650004 | Alt Telegram Handle: "bu4vs" |
+-------------------------------------------------------------+
|
v
+-------------------------------------------------------------+
| Russian Gov Database Records |
| Individual: Alexander Andreevich Yapaev (36), Izhevsk |
| Social Accounts: Pikabu ("4apai18"), Codeby ("Alexandr 4apaev")|
+-------------------------------------------------------------+
|
v
+-------------------------------------------------------------+
| Corporate Identity Linkage |
| Email: [email protected] | LinkedIn: Alexander Yapaev |
| Head of B2B Marketing at Uralenergo Udmurtia |
+-------------------------------------------------------------+
- Email & Repository Association: The registration email
[email protected](incorporating "1488", a known white supremacist numeric code) was queried via the OSINT service Epieos. The lookup showed the email was tied to an Apple account, a mobile number ending in 04, and a private GitHub profile named SantaMuerte, which contained a history of tracking and developing malware tools. - Telegram Identifier Tracing: The handle
@hastalamuerte18was mapped by Flashpoint to a permanent, unique Telegram user ID: 30907522. - Breached Database Matching: Constella Intelligence cross-referenced Telegram ID
30907522, matching it to an alternative handle, bu4vs, and a Russian phone number: +79127650004. - Government Database Cross-Referencing: Pivoting on the phone number
+79127650004across leaked Russian state databases revealed its registered owner: Alexander Andreevich Yapaev, a 36-year-old resident of Izhevsk. - Social Media & Alias Verification: Database records showed the phone number was used to register an account on the Russian content platform Pikabu under the name 4apai18. In Russian online culture, the digit "4" is commonly used as shorthand for the "ch" sound, linking "4apai" directly to the name "Chapaev"—matching the early Codeby forum alias Alexandr 4apaev.
- Corporate Footprint: Further investigations linked Yapaev to the primary email address
[email protected]. Epieos revealed that this address belongs to a LinkedIn profile for Alexander Yapaev, where he lists his official professional role as the Head of B2B Marketing at Uralenergo Udmurtia, one of Russia’s prominent corporate suppliers of electrical engineering and lighting equipment.
Requests for comment sent to Mr. Yapaev regarding these findings received no response.
Supporting Context & Metrics
RaaS Disruption & Economic Mechanics
The Gentlemen disrupted the traditional cybercrime landscape primarily through aggressive financial incentives. Standard RaaS operations typically operate on an 80/20 revenue-sharing model, where the platform administrator claims 20 percent of every ransom paid, leaving 80 percent for the affiliate who conducted the intrusion.
Standard RaaS Revenue Split:
Affiliate Share: ████████████████████ 80%
Administrator Cut: █████ 20%
'The Gentlemen' RaaS Revenue Split:
Affiliate Share: █████████████████████ 90%
Administrator Cut: ███ 10%
By slashing the administrator cut to 10 percent, The Gentlemen incentivized elite threat actors to abandon established programs and bring their high-volume attack vectors to the new platform.
Victim Metrics and Attack Vectors
According to security researchers at Check Point Software, the group’s market expansion has translated into significant victim counts:
- Total Claimed Victims (Mid-2025 to Present): 332 published targets
- Total Claimed Victims in 2026: 240+ published targets
- Global Ranking: #2 most active ransomware group by total victim volume
'The Gentlemen' Victim Surge Timeline
+-------------------------------------------------------+
| Mid-2025 to Late-2025 | █████████ 92 Victims |
| 2026 (Year-to-Date) | ████████████████████████ 240+ |
+-------------------------------------------------------+
The group primarily targets edge devices, specifically Internet-facing virtual private networks (VPNs) and firewalls. Once initial access is obtained, affiliates move laterally across the compromised corporate network, deploying the ransomware payload to achieve full-network encryption within a matter of hours.
Technical Blueprint & AI Integration
Complementary research published by threat intelligence firm PRODAFT provides additional context on the technical operation of The Gentlemen:
- Initial Access Delivery: Zeta88/Hastalamuerte frequently supplies initial access vectors directly to affiliates. This is accomplished primarily by distributing Fortinet SSL-VPN credentials harvested through brute-force campaigns or extracted from the group’s proprietary leak databases.
- Artificial Intelligence Integration: PRODAFT identified that the administrator relies on artificial intelligence (AI) tools to write, debug, and maintain the core ransomware source code, design affiliate tooling, and assist with post-exploitation tasks during live network intrusions.
Technical & Intelligence Analysis
Major security firms have published detailed technical breakdowns confirming the infrastructure and attribution behind The Gentlemen:
Check Point Software
Researchers noted that the 90/10 revenue split was the primary engine behind the syndicate’s rapid rise. Check Point’s analysis of the group’s backend infrastructure confirmed that Zeta88/Hastalamuerte manages the central command panel, compiles the custom ransomware binaries for affiliates, oversees financial payouts, and collects the 10 percent administrative levy.
PRODAFT
In an extensive intelligence report detailing the group’s internal operations, PRODAFT corroborated the administrator’s identity with "high confidence." Their research confirmed the administration’s reliance on automated initial-access credential distribution and highlighted the group’s integration of AI-assisted code generation to accelerate development cycles.
Intel 471 & Constella Intelligence
Forensic mapping by Intel 471 and Constella Intelligence pinpointed the administrator’s geographical history, showing consistent digital forum connections originating from Izhevsk, Russia, and linking those connections directly to Yapaev’s identity through leaked state database entries.
Operational Security and Geopolitical Realities
The case of Alexander Yapaev highlights a common pattern in cybercrime investigation: threat actors based in Russia frequently leave extensive trails of personal data exposed online.
OPERATIONAL SECURITY (OPSEC) DECAY LIFECYCLE
[Phase 1: Amateur Entry]
* Uses personal emails, local phone numbers, and regional handles.
* Joins training forums (@pntst) to learn basic pentesting.
* Leaves indelible footprints on low-tier hacking forums.
│
▼
[Phase 2: Capability Growth]
* Advances technical capabilities; adopts new handles (Zeta88/Hastalamuerte).
* Continues accessing platforms from personal IP pools (Izhevsk).
* Links specialized accounts to legacy personal infrastructure.
│
▼
[Phase 3: High-Volume Enterprise]
* Launches major criminal venture ('The Gentlemen').
* Operational success attracts high-level OSINT scrutiny.
* Historical OPSEC lapses allow researchers to trace back to real-world identity.
1. Early Career OPSEC Lapses
Most cybercriminals do not begin their careers as master manipulators. In their early years (2019–2020), operators are typically low-skilled, learning the basics while making fundamental operational security errors—such as registering crime forum accounts with personal email addresses, reusing social media handles, and authenticating from home IP addresses. By the time these individuals manage high-earning ransomware operations, their early digital footprints remain permanently logged across data breach repositories.
2. Russia’s Domestic Cyber Policy
Russian law enforcement agencies routinely tolerate or ignore illicit cyber operations occurring within their jurisdiction, provided the threat actors strictly avoid targeting Russian citizens, domestic corporations, or government institutions. In many cases, skilled cybercriminals are co-opted by state security services or operate under a framework of controlled impunity.
Because Russian cybercriminals face minimal risk of local prosecution or extradition to Western nations—provided they do not travel abroad and refrain from targeting domestic entities—they often place less emphasis on covering their online tracks, allowing historical OPSEC failures to persist unaddressed.
Future Outlook
The unmasking of Alexander Yapaev highlights a shift in the cybercrime landscape, where competitive financial incentives and automated AI assistance allow even small teams to achieve massive operational scale.
- Replicating the 90/10 Financial Model: The business success of The Gentlemen is likely to force rival RaaS syndicates to lower their administrative commissions. As a result, the market standard may shift toward 90/10 payouts to prevent affiliate churn.
- AI-Driven Ransomware Development: Zeta88’s use of artificial intelligence to automate locker creation and post-exploitation workflows sets a dangerous precedent. This approach lowers the technical barrier to entry for managing a complex RaaS network, enabling smaller teams to run large-scale extortion campaigns.
- Law Enforcement and Diplomatic Challenges: Despite public exposure and detailed attribution by global intelligence firms, operators residing within Russian borders remain largely shielded from foreign legal enforcement. Consequently, organizations globally must prepare for continued high-velocity attack campaigns targeting perimeter network devices, firewalls, and remote access systems.
