Quick Summary
AllegedExecutive Summary
The Malaysian Nuclear Agency, Malaysia’s national nuclear research and regulatory body, was targeted by the ransomware group The Gentlemen. The listing appeared on the group’s dark web portal on July 30, 2026, and was detected by SOCRadar’s Dark Web Monitoring. This incident represents a notable claim by the group, as it targeted a high-sensitivity public-sector organization, which is often a coveted target for ransomware operators. The agency’s role as a government and defense entity makes it a significant victim within the public sector. In the 60 days preceding this listing, The Gentlemen claimed approximately 175 victims, positioning them as one of the more active ransomware operations. Their typical targets are in the Manufacturing, Business Services, and Healthcare sectors, primarily located in the United States, India, and France. While a government agency falls outside their usual commercial focus, this targeting aligns with a discernible pattern involving Malaysian entities and public sector organizations. Previous victims exhibiting similar characteristics include The Garfield County Sheriff Office, Quanterm Logistics Sdn Bhd, SGS Malaysia, and Angel Hotel.
Technical Analysis
The surfaced stealer-log telemetry indicates a significant exposure for nuclearmalaysia[.]gov[.]my, with twenty-six records found within the queried sample. These records include nine employee credentials specifically related to the agency’s internal infrastructure, such as its organizational mail system, an internal client portal, an SSDL application, an HR/attendance system, and an Oracle Cloud tenant. Additionally, five records are for external-user credentials on organizational URLs, and another five are corporate credentials for third-party research and academic services. The exposure points predominantly to corporate intrusion risks. The timestamps on these logs, spanning July 26 to July 29, 2026, place them just days before the ransomware group’s listing. One employee account was found across more than a dozen internal and third-party systems, suggesting a potentially compromised workstation or extensive credential reuse by the individual. Infostealer-harvested credentials are a known pathway for groups like The Gentlemen to gain organizational access. Threat actors or access brokers typically acquire these logs, validate the corporate credentials, and then leverage them to access systems such as Microsoft 365, VPNs, or remote-access portals before proceeding with ransomware deployment. While this stealer-log evidence does not definitively confirm that The Gentlemen used these specific credentials, the direct exposure of email and cloud-tenant access on government infrastructure days before a leak-site listing is a strong indicator of the type of access this threat category exploits. Given the evidence of credential exposure immediately preceding the ransomware listing, immediate actions are recommended. This includes resetting passwords for all affected accounts, revoking active sessions and tokens associated with them, and conducting a forensic review of mail and Oracle Cloud access logs. Continued monitoring of dark web and stealer-log feeds for the organization is also advised.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.