# From Hastalamuerte to Zeta88: Investigators Unmask the Operator Behind The Gentlemen Ransomware Empire
A months-long investigation by multiple cybersecurity and intelligence firms has revealed the identity of the administrator behind The Gentlemen, one of 2026's most aggressive ransomware-as-a-service (RaaS) operations. The operator—a 36-year-old Russian named Alexander Andreevich Yapaev from Izhevsk—has built the second-most active ransomware gang in the world through an aggressive affiliate recruitment strategy and a lucrative financial model that is reshaping the economics of cybercriminal enterprise.
The emergence of The Gentlemen underscores how ransomware operations continue to mature into sophisticated, corporatized businesses that rival legitimate software companies in operational efficiency—complete with superior affiliate payouts, streamlined infrastructure, and aggressive marketing to attract top-tier criminal talent.
## The Threat: A Rapidly Growing RaaS Operation
Since its launch in mid-2025, The Gentlemen has claimed at least 332 published victims across its operational history, with more than 240 victims claimed in 2026 alone, according to research from Check Point Software. This volume places The Gentlemen as the second most active ransomware group by victim count during 2026, a remarkable rise for an organization that did not exist two years ago.
The group operates under a ransomware-as-a-service model, where criminal operators (called "affiliates") are given access to The Gentlemen's malware, infrastructure, and negotiation platforms in exchange for a percentage of ransom payments they successfully extract from victims. What sets The Gentlemen apart from competitors is a 90/10 affiliate revenue split—meaning affiliates receive 90 percent of ransom payments, while the operation retains 10 percent. Industry standard has historically been an 80/20 split favoring the operators.
This seemingly modest 10-percent difference has profound implications: experienced ransomware operators are actively defecting from established RaaS groups to join The Gentlemen, lured by the promise of higher payouts and—implicitly—an operation that is well-organized enough to deliver on those promises.
## Background and Context: The Rise of Ransomware-as-a-Service
The RaaS business model emerged in the mid-2010s as cybercriminals recognized that specialization and scale could multiply profits. Rather than executing attacks directly, operation founders build and maintain the technical infrastructure (malware, payment systems, data leak sites) while recruiting affiliates to find victims and execute intrusions.
For affiliates, RaaS offerings reduce operational overhead: they don't need to develop or maintain their own malware, manage cryptocurrency wallets, or operate victim negotiation forums. They simply need access to networks and the ability to deploy a provided payload.
For operation founders, RaaS creates a recurring revenue stream from dozens of affiliates, each generating multiple ransoms per month. A 10 percent cut of fifty affiliates, each collecting $500,000 in ransoms monthly, yields $2.5 million in monthly operator revenue—a scale that rivals mid-market software companies.
The Gentlemen's 90/10 split is a competitive weapon designed to poach experienced operators from rival RaaS groups by offering better financial terms. Check Point's researchers noted in April 2026 that this advantage is directly "accelerating the group's growth by attracting experienced operators from competing programs."
## Technical Details: Attack Pattern and Infrastructure
The Gentlemen targets a consistent technical pattern:
This speed-focused approach differs from some ransomware groups that conduct extended reconnaissance or move slowly to avoid detection. The Gentlemen's model assumes that rapid, widespread encryption creates sufficient pressure for payment regardless of stealth.
### Attribution Trail: From Hastalamuerte to Yapaev
The identification of the operator required forensic analysis across multiple data sources and digital footprints:
| Evidence Point | Finding |
|---|---|
| Username History | Hastalamuerte (2019+), later switched to Zeta88 (2022+) |
| Registration Location | Izhevsk, Udmurt Republic, western Russia |
| Email Address | hastalamuerte1488@protonmail.com (registered 2020) |
| Associated Accounts | Apple ID, GitHub account (SantaMuerte), Telegram ID 30907522 |
| Phone Number | +7-912-765-0004 (Russian number) |
| Real Identity | Alexander Andreevich Yapaev, age 36 |
Intel 471 traced the username Hastalamuerte across approximately a dozen cybercrime forums—including Exploit, Breachforums, Ramp_V2, BHF, Raidforums, and Nulled—registered between 2019 and the present day. The Raidforums registration in 2020 used the ProtonMail address hastalamuerte1488@protonmail.com; the "1488" suffix is a known numeric code associated with white supremacist ideology.
OSINT analysis of this email address via Epieos revealed connections to an Apple account and a phone number ending in -04. The same ProtonMail address is linked to a GitHub account under the username SantaMuerte, marked private but showing activity related to malware tools and exploits.
A critical link emerged through Telegram: in April 2020, Hastalamuerte posted on Nulled forum stating they could be contacted at the Telegram handle @hastalamuerte18. Threat intelligence firm Flashpoint attributed this handle the unique Telegram ID 30907522. Constella Intelligence then connected this Telegram ID to an alternate username, "bu4vs", and to the Russian phone number +7-912-765-0004.
A database lookup of this phone number—pulled from hacked Russian government databases available through Constella—returned records identifying the number's owner as Alexander Andreevich Yapaev, age 36, residing in Izhevsk. This convergence of digital evidence—email, Telegram, phone number, and geographic origin—represents a complete attribution chain from criminal handle to real identity.
## Implications for Organizations and the Threat Landscape
The unmasking of Yapaev raises several critical implications:
1. RaaS Operations Are Becoming More Professionalized
The Gentlemen's rapid growth and adoption of industry-standard business practices (competitive affiliate splits, dedicated infrastructure, professional payment processing) indicate that ransomware operations are evolving into mature criminal enterprises. This professionalization makes them more resilient and harder to disrupt than ad-hoc criminal groups.
2. Internet-Facing Infrastructure Is Under Sustained Pressure
The Gentlemen's explicit targeting of VPNs and firewalls means that any organization relying on remote access solutions without comprehensive security monitoring is at elevated risk. The speed of The Gentlemen's attacks (encryption within hours) suggests that traditional detection and response timelines may be insufficient.
3. Attribution Alone Does Not Equal Disruption
While identifying Yapaev is valuable for law enforcement, the identification does not immediately disable The Gentlemen's operations. The group's distributed affiliate model means that removing Yapaev alone may not significantly impact ongoing attacks—though it may support legal action and asset seizure by Russian or international authorities.
## Recommendations for Defense
Organizations should prioritize:
---
## HackWire Analysis
The identification of Alexander Yapaev exemplifies how modern ransomware operations are no longer faceless, distributed criminal networks—they are identifiable individuals running organized enterprises. The attribution chain (email → Telegram → phone → Russian database records → real name) demonstrates that OSINT and database intelligence can pierce operational security, even for actors operating out of Russia.
What makes this attribution significant beyond the individual is what it reveals about the market dynamics of cybercrime: The Gentlemen's 90/10 split is not just a tactical recruitment strategy; it signals that RaaS operations are competing for talent with the same intensity that legitimate technology companies compete for engineers. This competition is pushing payouts upward and forcing operators to offer better terms to remain viable.
For defenders, the implication is sobering. If ransomware operations are becoming more efficient, faster at execution, and more attractive to skilled operators, then organizations cannot rely on detection and response speed alone—they must assume breach and design networks for resilience and recovery. The traditional "detect and respond" model breaks down when encryption can spread across an enterprise in hours.
The Russian origin is also unsurprising but worth underlining: Yapaev's location in Izhevsk places him in a region that has become a hub for Russian cybercriminal activity, with relatively low risk of law enforcement interference. Unless international cooperation significantly escalates, Russian-based RaaS operators will continue operating with impunity, and the 90/10 model will likely become the new industry standard as other groups adopt it to remain competitive.
— HackWire Editorial
---
## Related Coverage