The Gentlemen Ransomware Admin Identified as Russian Marketer in Izhevsk

Alexander Andreevich Yapaev, a marketing professional in Izhevsk, linked via aliases and breach data to the ransomware-as-a-service group.

By Central
Open-source intelligence traced the admin's aliases across forums, Telegram, and government databases to a real identity.
Highlights
  • The Gentlemen ransomware group has become the second most active RaaS outfit by victim count in 2026.
  • Alexander Yapaev's online presence spanned aliases like Hastalamuerte and Zeta88 across multiple cybercrime forums.
  • The group's 90/10 revenue split attracts experienced operators from competing ransomware programs.

The administrator of The Gentlemen ransomware operation, a rapidly growing ransomware-as-a-service (RaaS) group that has become the second most active such outfit by victim count in 2026, has been identified as Alexander Andreevich Yapaev, a 36-year-old marketing professional living in Izhevsk, Russia. Open-source intelligence and breach data traced the administrator’s online aliases—Hastalamuerte and Zeta88—across multiple cybercrime forums, Telegram accounts, and compromised government databases, ultimately linking them to Yapaev’s real name, phone number, and LinkedIn profile, where he lists himself as head of B2B marketing at Uralenergo Udmurtia.

The Gentlemen’s Rapid Rise and Aggressive Recruitment

Check Point Software researchers have closely tracked The Gentlemen since its inception in mid-2025. The group operates a RaaS model that offers affiliates a 90/10 revenue split—significantly above the industry-standard 80/20—which has fueled its growth by attracting experienced operators from competing programs. As of early 2026, The Gentlemen claimed at least 332 published victims, with more than 240 of those occurring in 2026 alone. The group primarily targets Internet-facing devices such as VPNs and firewalls as entry points, and once inside, moves to encrypt entire networks within hours.

According to Check Point, the administrator and primary operator uses the nickname Zeta88 on Russian-language cybercrime forums and was previously known as Hastalamuerte. A breach of the group’s backend infrastructure confirmed that Hastalamuerte/Zeta88 assembles the locker and RaaS panel, manages payments, and receives 10 percent of all ransoms.

Tracing Hastalamuerte to a Real Identity

Intel 471 data shows that the user Hastalamuerte registered on Breachforums in January 2025 from an IP address in Izhevsk, the capital of Russia’s Udmurt Republic. The same individual, under the alias Zeta88, signed up on the English-language forum Breached in August 2022 from a different IP address also in Izhevsk. Hastalamuerte had earlier registered on Raidforums in 2020 using the email address [email protected]—the number 1488 is a known reference to white supremacy symbols. That Protonmail address was linked via Epieos to a GitHub account under the username SantaMuerte, which shows activity involving malware tools and exploits.

On the crime forum Nulled in April 2020, Hastalamuerte provided the Telegram handle @hastalamuerte18. Flashpoint identified this handle as having the unique Telegram ID 30907522. Constella Intelligence then linked that Telegram ID to another username—bu4vs—and to the Russian phone number 79127650004. Pivoting on that phone number in Constella returned records from hacked Russian government databases showing it belongs to Alexander Andreevich Yapaev, a 36-year-old from Izhevsk.

Further investigation through Constella revealed that the same phone number was used to create an account on the Russian social platform Pikabu under the name 4apai18. Searches in Intel 471 for the nickname SantaMuerte uncovered a 2020 Codeby forum account originally registered as Alexandr 4apaev. Yapaev’s email address [email protected] was connected via Epieos to a LinkedIn account for Alexander Yapaev, who lists himself as head of B2B marketing at Uralenergo Udmurtia. Yapaev did not respond to multiple requests for comment.

Why Russian Cybercriminals Often Leave a Trail

The apparent lack of operational security by many Russian cybercriminals stems from several factors. Most did not set out to become major criminals; they were drawn into the scene gradually as their skills developed. Moreover, the Russian government generally either co-opts or ignores cybercriminal activity within its borders as long as hackers avoid targeting Russian businesses and citizens. Successful cybercriminals in Russia are therefore largely insulated from prosecution by foreign law enforcement, provided they make occasional payoffs to the right people and do not travel abroad. Additionally, early career mistakes—when the hacker is less savvy and has less to lose—often leave lasting digital traces that investigators can exploit years later. Hastalamuerte’s own early posts on crime forums from 2019–2020 show a relatively unsophisticated hacker still learning penetration testing tools, struggling with basic techniques in a multi-month training program.

What This Means for Organizations at Risk

The identification of The Gentlemen’s administrator does not immediately dismantle the group, but it provides law enforcement with actionable intelligence and underscores the importance of securing Internet-facing devices. Organizations should prioritize patching VPNs and firewalls, implementing multi-factor authentication, and maintaining offline backups to reduce exposure to network-encrypting ransomware. For individuals and businesses concerned about ransomware attacks, deploying a multi-layer endpoint protection solution with real-time behavioral analysis and enabling network segmentation can limit the blast radius of an intrusion.

Readers affected by data breaches connected to ransomware incidents should immediately change passwords for all online accounts, enable two-factor authentication wherever supported, and monitor financial accounts and credit reports for signs of fraud. Using a reputable no-log VPN service on public Wi-Fi networks adds an additional layer of protection against credential interception. While The Gentlemen’s administrator may have been identified, the group’s infrastructure and affiliate network remain active, making vigilance and proactive defense the most effective countermeasures.

Share This Article