A hacking collective called The Gentlemen has climbed to become the second most prolific ransomware operation when measured by number of victims, drawing in skilled cybercriminals through an aggressive recruitment model that offers affiliates a staggering 90 percent cut of every ransom collected. This article explores digital breadcrumbs that may point to the true identity of the individual running The Gentlemen ransomware group.
An image produced and posted by The Gentlemen ransomware group’s administrator, Hastalamuerte, on Breachforums in May 2026. Credit: ke-la.com.
Analysts at the cybersecurity company Check Point Software have been tracking The Gentlemen’s operations closely. The group operates as a “ransomware-as-a-service” (RaaS) platform, generously compensating affiliates who help distribute the group’s malicious software.
“The 90/10 split in favor of affiliates — as opposed to the typical 80/20 arrangement seen elsewhere — is fueling the group’s rapid expansion by luring seasoned operators away from rival programs,” the researchers noted in their April report.
According to Check Point, The Gentlemen currently ranks as the second most active ransomware outfit by victim tally this year, having published at least 332 victim listings since the group first appeared in mid-2025, with over 240 of those occurring in 2026 alone.
Check Point reports that the group’s initial foothold comes through Internet-exposed appliances — such as VPN gateways and firewalls — and once inside, they waste no time encrypting entire corporate networks within a matter of hours.
Check Point identifies the group’s administrator and lead operator by the alias Zeta88 on Russian-language underground forums, and notes that this same individual previously went by the handle Hastalamuerte. Check Point stated that a compromise of the group’s backend systems confirmed that Hastalamuerte/Zeta88 is the person responsible for building the ransomware locker and RaaS dashboard, handling payment processing, and effectively serving as the program’s administrator — collecting 10 percent from every ransom payment.
WHO IS HASTALAMUERTE?
The threat intelligence provider Intel 471 indicates that the Hastalamuerte persona is fluent in both Russian and English, and has created accounts on nearly a dozen underground cybercrime forums from 2019 onward, including Exploit, Breachforums, Ramp_V2, BHF, Raidforums, and Nulled.
Intel 471 shows that Hastalamuerte joined Breachforums in January 2025 from an IP address located in Izhevsk, the capital of Russia’s Udmurt Republic. Similarly, the alias Zeta88 registered on the English-language cybercrime forum Breached in August 2022, also from a different IP address in Izhevsk.
Intel 471 found that Hastalamuerte signed up on Raidforums in 2020 using the email hastalamuerte1488@protonmail.com (the number 1488 is a widely recognized numeric code tied to white supremacist ideology). A search of this address through the open-source intelligence tool Epieos reveals it is associated with an Apple account and a phone number ending in 04.
Epieos also indicates that the same Protonmail address is tied to a GitHub profile under the name SantaMuerte. While the account is set to private, an analysis of its activity history shows the user monitoring and contributing to the development of various malware tools and exploit frameworks.
In April 2020, Hastalamuerte posted on the criminal forum Nulled that they could be reached via Telegram at @hastalamuerte18, and the threat intelligence firm Flashpoint confirmed this username carries the unique Telegram ID 30907522 [full disclosure: Flashpoint is an advertiser on this blog].
The breach monitoring service Constella Intelligence found that Hastalamuerte’s Telegram ID is linked to another handle — “bu4vs” — as well as the Russian mobile number 79127650004. Cross-referencing this phone number through Constella across multiple leaked Russian government databases returned records tying it to one Alexander Andreevich Yapaev, a 36-year-old resident of Izhevsk.
Constella further found that this phone number was used to register an account on the Russian social network Pikabu under the display name “4apai18,” and that Mr. Yapaev has created accounts across various websites using either the generic surname Ivanov or “Chapaev” (in Russian, the digit 4 is frequently used as a phonetic substitute for the letter “ch”).
A search within Intel 471 for cybercrime forum members using the alias SantaMuerte surfaced an identically named account created in 2020 on the Russian hacking forum Codeby. Intel 471 shows this user initially registered on Codeby under the rather conspicuous nickname Alexandr 4apaev.
Constella found that Mr. Yapaev regularly used the email address bu4vs@mail.ru. Meanwhile, Epieos shows this same address is connected to a LinkedIn profile belonging to Alexander Yapaev, who describes himself as the head of B2B marketing at Uralenergo Udmurtia, one of Russia’s largest manufacturers of electrical and lighting equipment.
Mr. Yapaev did not respond to repeated requests for comment.
Almost every time we publish one of these Breadcrumbs investigations, readers wonder why so many cybercriminals operating out of Russia seem to make little effort to conceal their real-world identities. The reality is that — Russian or otherwise — most of these individuals didn’t set out to become masterminds of cybercrime. Instead, they were gradually pulled into the underground over several years as their technical abilities grew and evolved.
Another key factor is that the Russian government tends to either co-opt or turn a blind eye to cybercriminal activity within its borders, so long as the hackers refrain from targeting Russian companies and citizens. Consequently, successful cybercriminals in Russia are typically shielded from prosecution and arrest by foreign law enforcement — provided they occasionally pay off the right officials and avoid traveling outside the country. And those who plan to strictly follow these unwritten rules may (at least in the beginning) be less worried about masking their digital footprints.
But the most straightforward explanation is that cybercriminals of all backgrounds tend to commit a range of basic operational security blunders early in their careers, when they are less experienced and have far less at stake from their carelessness. A review of Hastalamuerte’s earliest posts on criminal forums (around 2019–2020) paints a picture of a relatively unskilled and inexperienced hacker still trying to find their footing and build a reputation within these communities.
For instance, in June 2020, Hastalamuerte’s Telegram account enrolled in a months-long training channel (@pntst) to learn how to use widely adopted penetration testing tools, and their frank posts to this hacker training group reveal Hastalamuerte having difficulty using these tools competently. A Google-translated archive of Hastalamuerte’s messages to @pntst is available here.



