ransomware
~/ › ransomware › article
TheGentlemen Ransomware Claims Attack on Israeli Battery Maker Amicell
> By Haider | Aug 04, 2026 | 3 min read
The ransomware collective operating under the designation TheGentlemen has purportedly listed Israeli energy solutions manufacturer Amicell , Amit Industries Ltd. on its dark web extortion portal. The group claims to have successfully infiltrated the company’s internal networks and exfiltrated a significant volume of sensitive corporate data. The alleged listing was first detected on July 31, 2026, alongside threats to publish the stolen files if Amicell refuses to enter into ransom negotiations.

Amicell (Amit Industries Ltd.) specializes in the design and manufacture of advanced custom battery packs and Battery Management Systems (BMS) for industrial, commercial, and defense-adjacent applications. The specialized nature of their manufacturing operations lends added severity to any potential compromise of intellectual property or supply chain data. As of early August 2026, the claims remain unverified, and Amicell has not issued a public statement regarding the incident.
Threat Context: TheGentlemen Ransomware Operations
TheGentlemen is a financially motivated Ransomware-as-a-Service (RaaS) operation that first emerged in the mid-2025 cyber threat landscape. According to independent threat intelligence trackers, the group was tied for the highest number of claimed victims (119) globally in July 2026, demonstrating a highly aggressive and rapidly expanding operational tempo.
Security analysts note that TheGentlemen affiliates differentiate themselves through the use of sophisticated custom tooling designed to evade modern endpoint detection and response (EDR) solutions. A hallmark of their recent campaigns involves the deployment of Bring-Your-Own-Vulnerable-Driver (BYOVD) attacks. By installing legitimately signed but inherently vulnerable kernel-level drivers, the attackers can effectively disable or blind corporate antivirus and EDR agents before executing their encryption payloads.
Industrial and Energy Sectors in the Crosshairs
The targeting of Amicell aligns with a broader trend of ransomware operators focusing heavily on the manufacturing and energy sectors. These industries rely on complex supply chains and just-in-time production schedules, making them highly sensitive to operational downtime. Threat actors leverage this urgency, calculating that industrial firms are more likely to pay extortions to avoid catastrophic disruptions to production lines and delayed client deliverables.
In addition, Israel’s industrial sector has faced a heightened threat landscape throughout 2026, enduring both financially motivated RaaS attacks and state-aligned hacktivist campaigns aiming to disrupt the nation’s critical economic infrastructure.
Actionable Defense: Mitigating BYOVD and RaaS Threats
For industrial manufacturers operating in high-threat environments, defending against sophisticated groups like TheGentlemen requires moving beyond basic perimeter defenses. Organizations should consult the NIST Cybersecurity Framework to build resilient architectures.
- Block Vulnerable Drivers: To counter BYOVD attacks, administrators must actively maintain and enforce the Microsoft Vulnerable Driver Blocklist (via Windows Defender Application Control). This prevents attackers from loading known vulnerable kernel drivers even if they achieve administrative privileges.
- Network Segmentation (IT/OT Convergence): Isolate Operational Technology (OT) and Industrial Control Systems (ICS) networks from the corporate IT environment. A breach in the office network should never provide a lateral pathway to the manufacturing floor.
- Immutable and Air-Gapped Backups: Maintain frequent, immutable backups stored in air-gapped or offline environments. This ensures that even if TheGentlemen successfully encrypt production systems, recovery is possible without engaging the attackers.
- Privilege Access Management (PAM): Enforce strict Least Privilege policies and utilize PAM solutions to heavily monitor and restrict administrative accounts, which are required for attackers to disable security tools.
Disclaimer: The information presented in this threat intelligence report is for educational and cybersecurity research purposes only. CyberAsia reports on cyber incidents to help organizations understand and defend against emerging threats. We do not provide hacking instructions, host stolen data, or endorse illegal activities.
Mitigation & Prevention Strategies
Given the dual-extortion tactics often employed by modern ransomware operators, reactive backups are no longer sufficient. Organizations must adopt proactive measures:
- Zero Trust Architecture: Enforce strict network segmentation to limit lateral movement. Ransomware often exploits flat networks to reach critical domain controllers.
- MFA & Credential Hygiene: Mandate Multi-Factor Authentication (MFA) across all administrative accounts and VPN gateways to block initial access brokers.
- Immutable Backups: Maintain offline, immutable backups that cannot be encrypted or deleted by compromised administrative accounts.
> INTELLIGENCE_NOTICE
The report above detailing TheGentlemen Ransomware Claims Attack on Israeli Battery Maker Amicell is part of the CyberAsia public archive. For organizations requiring Indicators of Compromise (IoCs), YARA signatures, and specialized malware containment guidelines for ransomware threats, please refer to our Secure Drop or contact the research desk.
> related_intel --suggest
ransomware
ransomware
Gunra Ransomware Exploits Fortinet Zero-Days
> read
ransomware