>samit_hota
Back to security news

Security News · SN-2026-384

HIGHOPEN

AnMed Cyberattack Escalates as The Gentlemen Ransomware Hijacks Social Media

Affected: AnMed · Network Edge Devices · Endpoint Security Tools

Samit Hota·
#news#ransomware#anmed

In an aggressive move to force payment following the AnMed cyberattack, operators behind The Gentlemen ransomware hijacked the healthcare provider’s official Facebook page to broadcast extortion demands. The nonprofit network—which operates four hospitals and dozens of clinics across South Carolina and Georgia—first reported a malware-driven network disruption on July 26. Two weeks into the recovery process, at least 10 facilities remain closed to patient appointments, illustrating the severe operational fallout typical of modern ransomware incidents in the healthcare sector.

Social Media Hijacking and Extortion Tactics

The hijacking of AnMed’s Facebook presence represents a public pivot in double-extortion strategies. Messages purporting to be from The Gentlemen ransomware group appeared directly on the hospital chain’s social media feed before Meta removed the page entirely.

The threat actors claimed to have exfiltrated 6 terabytes of unencrypted files from AnMed’s internal network. According to the posts, the stolen data includes highly sensitive records related to mental health care, sexual assault reports, abortion procedures, and internal sexual harassment complaints. While the threat group did not release sample data to verify the exfiltration at the time of posting, the nature of the claimed dataset appears calculated to generate maximum reputational pressure and regulatory exposure under federal privacy laws. AnMed maintains that it has not yet confirmed the full scope of potential impact on patient information.

Threat Actor Profile: The Gentlemen Ransomware

The Gentlemen has rapidly emerged as one of the most active ransomware-as-a-service (RaaS) operations since first surfacing in the second half of 2025. Security researchers attribute the founding of the group to a threat actor operating under the moniker “hastalamuerte,” previously known as an affiliate for the Qilin ransomware cartel.

The syndicate’s growth trajectory has been notable:

  • High Victim Volume: Data from security firm CheckPoint indicates that ransomware associated with The Gentlemen was deployed against 332 victim organizations in the first five months of this year alone.
  • Industrial Focus: Operational technology security firm Dragos tracked 125 attacks by the group against industrial organizations during the second quarter of 2026, placing them as the third most active ransomware strain in that sector.
  • Affiliate-Centric Financial Model: Leaked internal files analyzed by CheckPoint reveal an unusually generous revenue share, where affiliates who execute intrusions retain 90 percent of paid ransoms, leaving 10 percent for core developers.

Technical Mechanics and Exploitation Vectors

The Gentlemen relies heavily on opportunistic exploitation and robust defense evasion to compromise targets and maintain persistence across corporate environments.

Edge Device Compromise

Initial access is predominantly achieved through exposed edge infrastructure, including firewalls, Virtual Private Network (VPN) appliances, and web management panels. Affiliates gain access through three main vectors:

  1. Direct credential brute-forcing against exposed login interfaces lacking multi-factor authentication (MFA).
  2. Exploitation of public-facing vulnerabilities in network perimeter devices.
  3. Acquisition of pre-established network footholds from initial access brokers (IABs).

Internal Escalation and Defense Evasion

Once inside the perimeter, affiliates work quickly to obtain domain administrator credentials, enumerate Active Directory, and disable centralized endpoint security software prior to staging data exfiltration and binary deployment.

To bypass Endpoint Detection and Response (EDR) platforms, the group frequently employs Bring Your Own Vulnerable Driver (BYOVD) attacks. As highlighted in research by Expel’s Marcus Hutchins, The Gentlemen’s toolkit includes sophisticated automation to exploit vulnerabilities in obscure third-party, digitally signed kernel drivers. By loading a legitimately signed driver containing a known security flaw, the malware executes code at the kernel level (Ring 0), allowing operators to unhook security agents, kill protected processes, and strip security software of its monitoring capabilities.

Operational Impact and Blast Radius in Healthcare

The disruption at AnMed highlights the significant blast radius when core IT services are locked or severed in a medical setting. Beyond administrative outages, the shutdown of core health information systems forces clinical staff to revert to manual paper workflows, delays diagnostic processing, and halts non-emergency procedures.

The operational shutdown of 10 outpatient facilities demonstrates that ransomware attacks on healthcare networks are rarely contained to isolated segments. Interconnected scheduling, electronic health record (EHR) databases, and Active Directory domains mean that containment actions often necessitate disconnecting widespread network segments across regional clinic footprints.

Targeted Mitigations and Hardening Guidance

To protect against the specific intrusion patterns and defense evasion techniques deployed by groups like The Gentlemen, security teams should implement the following technical controls:

  • Harden Perimeter Edge Appliances: Audit all internet-facing firewalls, SSL-VPNs, and web portals. Enforce strict phishing-resistant MFA (such as FIDO2/WebAuthn) for all remote access points, block single-factor legacy authentication protocols, and restrict administrative management interfaces to trusted internal IP ranges.
  • Block Vulnerable Drivers (BYOVD Mitigation): Enable Hypervisor-Protected Code Integrity (HVCI) or Memory Integrity in Windows environments, and enforce Microsoft’s Vulnerable Driver Blocklist to prevent kernel-level termination of EDR services by third-party drivers.
  • Restrict Administrative Privileges: Implement strict Tiered Administration models to prevent edge device service accounts or compromised local accounts from easily escalating to enterprise domain admin rights.
  • Protect External Brand Assets: Enforce hardware-key MFA and centralized password management across corporate social media and marketing accounts to prevent secondary brand hijacking during active incident response windows.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call