Quick Summary
AllegedExecutive Summary
thegentlemen listed Nutrypollo, a manufacturing company based in Mexico that operates at nutrypollo[.]com.mx, on its leak site on August 30, 2026. The ransomware group alleged unauthorized access to the company’s systems and data. This claim has not been independently verified. Nutrypollo’s operational focus within the manufacturing sector in Mexico aligns with the known targeting patterns of thegentlemen. Over the past 60 days, thegentlemen has claimed 248 victims, with a significant focus on the Manufacturing and Technology sectors. Their primary victim countries include the United States, the United Kingdom, and Germany. Nutrypollo’s profile as a manufacturing entity in Mexico fits within the established targeting strategy of this threat actor, suggesting a continuation of their operational modus operandi.
Technical Analysis
SOCRadar CTI’s analysis of stealer-log data indicated a “severe_exposure_in_sample” verdict for Nutrypollo. Telemetry identified two corporate third-party credentials associated with productupload[.]com, suggesting a potential compromise of a workstation. The timestamps for these credentials range from November 23, 2025, to February 22, 2026, which is consistent with the typical timeline for pre-attack reconnaissance activities. The exposure of credentials at a third-party integration point like productupload[.]com is a common tactic employed by threat actors before deploying ransomware. thegentlemen operators frequently utilize stolen credentials to expedite initial access, reduce their dwell time within a compromised network, and evade detection during the critical stages of an intrusion. Next Steps Rotate the credentials associated with productupload[.]com immediately. Conduct an audit of authentication logs to identify any anomalous access during the period between November 23, 2025, and February 22, 2026. Implement multi-factor authentication (MFA) for all remote access points and third-party integration endpoints.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.