<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Analysis and recommendations &#8211; Bitfinance</title>
	<atom:link href="https://bitfinance.news/en/etiqueta/analysis-and-recommendations/feed/" rel="self" type="application/rss+xml" />
	<link>https://bitfinance.news</link>
	<description>Fintech &#38; new economy info</description>
	<lastBuildDate>Mon, 13 Apr 2026 13:18:44 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://bitfinance.news/wp-content/uploads/2025/01/favicon-64.png</url>
	<title>Analysis and recommendations &#8211; Bitfinance</title>
	<link>https://bitfinance.news</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>New generation of ransomware targets Latin America with tailored attacks that cause severe damage</title>
		<link>https://bitfinance.news/en/new-generation-of-ransomware-targets-latin-america-with-tailored-attacks-that-cause-severe-damage/</link>
		
		<dc:creator><![CDATA[Marilin Pino]]></dc:creator>
		<pubDate>Mon, 13 Apr 2026 15:00:28 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Financial security]]></category>
		<category><![CDATA[Analysis and recommendations]]></category>
		<category><![CDATA[attacks in 17 countries]]></category>
		<category><![CDATA[customized and ultra-adaptive attacks]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[double extortion]]></category>
		<category><![CDATA[economic and reputational damage]]></category>
		<category><![CDATA[ESET]]></category>
		<category><![CDATA[ESET Latin America]]></category>
		<category><![CDATA[ESET Venezuela]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[Martina López]]></category>
		<category><![CDATA[New generation of ransomware]]></category>
		<category><![CDATA[The Gentlemen ransomware]]></category>
		<category><![CDATA[Venezuela]]></category>
		<guid isPermaLink="false">https://bitfinance.news/?p=120744</guid>

					<description><![CDATA[<div style="margin-bottom:20px;"><img width="755" height="425" src="https://bitfinance.news/wp-content/uploads/2026/04/Imagen-referencial-principal.-que-es-el-ransomware-como-funciona.-Suministrada-por-ESET-y-Comstat-Rowland.jpeg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="ESET advierte sobre un nuevo modelo de robo de información, silencioso y mucho más peligroso, que tiene a Latinoamérica dentro de sus objetivos. Se caracteriza por sus campañas dirigidas y adaptativas. Hacen gran daño económico y reputacional" decoding="async" fetchpriority="high" srcset="https://bitfinance.news/wp-content/uploads/2026/04/Imagen-referencial-principal.-que-es-el-ransomware-como-funciona.-Suministrada-por-ESET-y-Comstat-Rowland.jpeg 755w, https://bitfinance.news/wp-content/uploads/2026/04/Imagen-referencial-principal.-que-es-el-ransomware-como-funciona.-Suministrada-por-ESET-y-Comstat-Rowland-300x169.jpeg 300w" sizes="(max-width: 755px) 100vw, 755px" /></div><p>The Gentlemen ransomware attacked more than 250 victims in 17 countries, including Mexico, Colombia, Chile, and Argentina, and represents a new era of customized and ultra-adaptive attacks. Unlike other groups, this Ransomware as a Service (RaaS) studies the specific defenses of its victims and adapts its tools during the campaign to overcome existing controls. ESET, [&#8230;]</p>
<p>La entrada <a rel="nofollow" href="https://bitfinance.news/en/new-generation-of-ransomware-targets-latin-america-with-tailored-attacks-that-cause-severe-damage/">New generation of ransomware targets Latin America with tailored attacks that cause severe damage</a> apareció primero en <a rel="nofollow" href="https://bitfinance.news">Bitfinance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style="margin-bottom:20px;"><img width="755" height="425" src="https://bitfinance.news/wp-content/uploads/2026/04/Imagen-referencial-principal.-que-es-el-ransomware-como-funciona.-Suministrada-por-ESET-y-Comstat-Rowland.jpeg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="ESET advierte sobre un nuevo modelo de robo de información, silencioso y mucho más peligroso, que tiene a Latinoamérica dentro de sus objetivos. Se caracteriza por sus campañas dirigidas y adaptativas. Hacen gran daño económico y reputacional" decoding="async" srcset="https://bitfinance.news/wp-content/uploads/2026/04/Imagen-referencial-principal.-que-es-el-ransomware-como-funciona.-Suministrada-por-ESET-y-Comstat-Rowland.jpeg 755w, https://bitfinance.news/wp-content/uploads/2026/04/Imagen-referencial-principal.-que-es-el-ransomware-como-funciona.-Suministrada-por-ESET-y-Comstat-Rowland-300x169.jpeg 300w" sizes="(max-width: 755px) 100vw, 755px" /></div><p style="text-align: justify;">The <strong>Gentlemen ransomware</strong> attacked <a href="https://www.ransomware.live/groupstats/thegentlemen" target="_blank" rel="noopener">more than 250 victims</a> in <strong>17 countries, including Mexico, Colombia, Chile, and Argentina,</strong> and represents a <strong>new era of customized and ultra-adaptive attacks.</strong> Unlike other groups, this <em>Ransomware as a Service (RaaS)</em> studies the specific defenses of its victims and adapts its tools during the campaign to overcome existing controls. <strong><a href="https://www.eset.com/latam/" target="_blank" rel="noopener">ESET</a></strong>, a leading company in proactive threat detection, analyzes the new landscape of ransomware groups and warns how this disciplined, meticulous, and highly methodical organization has disrupted traditional approaches to become <strong>one of the most active threats since July 2025.</strong></p>
<p style="text-align: justify;"><em>“It is an emerging <a href="https://www.welivesecurity.com/la-es/2022/02/23/ransomware-as-a-service-raas-que-es-como-funciona/" target="_blank" rel="noopener">Ransomware-as-a-Service group</a> that burst onto the cybercrime scene in mid-2025. Unlike other groups with more sloppy or rustic aesthetics, The Gentlemen stands out for its polished brand identity. It even maintains a leak site on the dark web with a professional logo and a slogan that reinforces its image as a disciplined and highly detail-oriented organization. This professionalism is not merely aesthetic; it is reflected in the precision of its attacks and the technical quality of its tools,”</em> says <strong>Martina Lopez, cybersecurity researcher at ESET Latin America.</strong></p>
<p style="text-align: justify;">Their operating model is based on <strong>double extortion,</strong> a tactic where they not only encrypt the victim&#8217;s files to block access, but also exfiltrate confidential data before encryption. Once they possess the information, they <strong>threaten to publish it on their leaks site if a ransom is not paid.</strong> This strategy puts massive<strong> pressure on companies, especially those that cannot afford a public data breach.</strong></p>
<p style="text-align: justify;">A ransomware attack by The Gentlemen <strong>typically begins by exploiting exposed internet access points</strong> (systems with open administration) <strong>or using previously stolen credentials.</strong> Once inside, they deploy tools to scan the internal network, understand how the company is organized, and identify users with elevated privileges, especially those with full access to the systems.</p>
<p style="text-align: justify;">To move within the network and escalate the attack, they use tools that allow them to remotely execute actions on multiple computers and modify key configurations. In this way, they manage to distribute the ransomware simultaneously across all connected devices, further weakening security mechanisms to facilitate remote access and control.</p>
<p style="text-align: justify;">In the final stage, <strong>they combine two critical actions: first, they steal sensitive information and send it to external servers in encrypted form; second, they lock down systems using encryption.</strong> Once the attack is complete, they <strong>execute processes designed to erase their tracks: they delete activity logs, remote connections, and any evidence that could allow them to reconstruct what happened,</strong> thus hindering subsequent investigations.</p>
<p style="text-align: justify;"><a href="https://www.ransomware.live/id/Sk4gQWNlcm9zQHRoZWdlbnRsZW1lbg==" target="_blank" rel="noopener">Their first documented victim</a> was registered on June 30, 2025, and since then, their activity has not ceased. They have affected <strong>critical sectors such as manufacturing, construction, healthcare, insurance, and financial services.</strong></p>
<figure id="attachment_120720" aria-describedby="caption-attachment-120720" style="width: 1300px" class="wp-caption alignnone"><img decoding="async" class="wp-image-120720 size-full" src="https://bitfinance.news/wp-content/uploads/2026/04/Para-acompanar-texto-imagen-referencial-1.png" alt="[Image: Detail of victims of The Gentlemen ransomware. Source: ransomware.live]" width="1300" height="687" srcset="https://bitfinance.news/wp-content/uploads/2026/04/Para-acompanar-texto-imagen-referencial-1.png 1300w, https://bitfinance.news/wp-content/uploads/2026/04/Para-acompanar-texto-imagen-referencial-1-300x159.png 300w, https://bitfinance.news/wp-content/uploads/2026/04/Para-acompanar-texto-imagen-referencial-1-1024x541.png 1024w, https://bitfinance.news/wp-content/uploads/2026/04/Para-acompanar-texto-imagen-referencial-1-768x406.png 768w" sizes="(max-width: 1300px) 100vw, 1300px" /><figcaption id="caption-attachment-120720" class="wp-caption-text">(Detail of victims of The Gentlemen ransomware. Source: ransomware.live)</figcaption></figure>
<p style="text-align: justify;"><strong>Geographically, their impact is global, but the most affected countries include the United States and Thailand, followed by India, Mexico, Colombia, Spain, and France.</strong> This distribution suggests that the group takes advantage of access opportunities wherever they arise, without an apparent geopolitical agenda.</p>
<p style="text-align: justify;">In mid-March 2026, they published on their website the attack on two organizations in Colombia in the healthcare and media sectors. During February, <a href="https://x.com/BirminghamCyber/status/2027038756096581697/photo/1" target="_blank" rel="noopener">they attacked a government scientific research institute in Argentina</a>, and in March,<a href="https://x.com/_venarix_/status/2033632495502004577" target="_blank" rel="noopener"> they claimed responsibility for an attack</a> on an organization in Chile. According to the <a href="https://www.ransomware.live/map?q=thegentlemen&amp;year=full" target="_blank" rel="noopener">ransomware.live website</a>, they also reported victims in<strong> Brazil, Peru, Ecuador, Venezuela, Guatemala, the Dominican Republic, Costa Rica, and Panama.</strong></p>
<figure id="attachment_120718" aria-describedby="caption-attachment-120718" style="width: 921px" class="wp-caption alignnone"><img decoding="async" class="wp-image-120718 size-full" src="https://bitfinance.news/wp-content/uploads/2026/04/Imagen-referencial-2-para-acompanar-cuerpo-del-texto.jpg" alt="The Gentlemen ransomware reports on its website the attack on a television channel" width="921" height="1203" srcset="https://bitfinance.news/wp-content/uploads/2026/04/Imagen-referencial-2-para-acompanar-cuerpo-del-texto.jpg 921w, https://bitfinance.news/wp-content/uploads/2026/04/Imagen-referencial-2-para-acompanar-cuerpo-del-texto-230x300.jpg 230w, https://bitfinance.news/wp-content/uploads/2026/04/Imagen-referencial-2-para-acompanar-cuerpo-del-texto-784x1024.jpg 784w, https://bitfinance.news/wp-content/uploads/2026/04/Imagen-referencial-2-para-acompanar-cuerpo-del-texto-768x1003.jpg 768w" sizes="(max-width: 921px) 100vw, 921px" /><figcaption id="caption-attachment-120718" class="wp-caption-text">The Gentlemen ransomware reports on its website the attack on a television channel</figcaption></figure>
<h3 style="text-align: left;">ESET provides the following list of recommendations to protect yourself from The Gentlemen ransomware:</h3>
<ul>
<li style="text-align: justify;"><strong>Reduce internet exposure:</strong> review which systems are accessible from outside and close any unnecessary access, especially administration panels or remote access.</li>
<li style="text-align: justify;"><strong>Protect credentials:</strong> use unique and strong passwords, enable<a href="https://www.welivesecurity.com/la-es/2022/12/22/doble-factor-autenticacion-que-es-porque-lo-necesito/" target="_blank" rel="noopener"> two-factor authentication</a>, and monitor any suspicious logins.</li>
<li style="text-align: justify;"><strong>Keep everything up to date:</strong> apply <a href="https://www.welivesecurity.com/la-es/2023/03/15/razones-mantener-software-dispositivos-actualizados/" target="_blank" rel="noopener">security patches</a> to operating systems, servers, and applications. Many of their intrusions exploit known vulnerabilities.</li>
<li style="text-align: justify;"><strong>Detect anomalous behavior:</strong> Implement solutions that allow you to identify unusual activity within the network, such as after-hours access or unexpected remote executions.</li>
<li style="text-align: justify;"><strong>Limit privileges:</strong> Not all users need full access. Reducing permissions minimizes the impact if an account is compromised.</li>
<li style="text-align: justify;"><strong>Segment the network:</strong> Separating critical systems prevents an attacker from moving freely and compromising the entire infrastructure.</li>
<li style="text-align: justify;"><strong>Perform backups:</strong> Carry out regular backups and store them in isolation, verifying that they can be restored correctly.</li>
<li style="text-align: justify;"><strong>Train the team:</strong> Human error remains one of the main entry points. Awareness is key.</li>
</ul>
<p style="text-align: justify;"><em>“In a scenario where attacks are no longer massive but personalized, the question is no longer whether an organization can be targeted, but when. Understanding how groups like The Gentlemen operate is the first step to anticipating a threat that no longer gives warning,”</em> concludes Lopez from ESET.</p>
<p style="text-align: left;">ESET invites you to learn more about cybersecurity by visiting: <a href="https://www.welivesecurity.com/es/" target="_blank" rel="noopener">https://www.welivesecurity.com/es/.</a></p>
<p style="text-align: left;">For useful preventative information, visit <a href="https://www.eset.com/ve/" target="_blank" rel="noopener">https://www.eset.com/ve/</a> and follow them on social media @eset_ve, Instagram (<a href="https://www.instagram.com/esetla/" target="_blank" rel="noopener">@esetla</a>), and Facebook (<a href="https://www.facebook.com/ESETLA" target="_blank" rel="noopener">ESET</a>.</p>
<p style="text-align: left;">Information and images provided by ESET and Comstat Rowland</p>
<p style="text-align: left;"><em><strong>Follow our news on Google!</strong></em><em> For current, interesting, and accurate information, </em><a href="https://www.google.com/search?q=site:bitfinance.news&amp;tbm=nws&amp;tbs=sbd:1" target="_blank" rel="noopener"><strong><em>click here</em></strong></a><em> to see all the content on <strong>Bitfinance.news</strong>. You can also find us on </em><a href="https://twitter.com/BitFinance_News" target="_blank" rel="noopener"><strong><em>X/Twitter</em></strong></a><em> and </em><a href="https://www.instagram.com/bitfinancenews/?hl=es" target="_blank" rel="noopener"><strong><em>Instagram</em></strong></a></p>
<p>La entrada <a rel="nofollow" href="https://bitfinance.news/en/new-generation-of-ransomware-targets-latin-america-with-tailored-attacks-that-cause-severe-damage/">New generation of ransomware targets Latin America with tailored attacks that cause severe damage</a> apareció primero en <a rel="nofollow" href="https://bitfinance.news">Bitfinance</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
