Compiled from this incident record and the threat intelligence profile for Thegentlemen. Figures and technique mappings are quoted from the source data, not inferred.
Thegentlemen dark web leak site listed Craisa on 26 September 2026. Craisa is a Costa Rican distributor that offers machinery from CASE IH and CASE Construction Equipment, servicing agriculture, construction, and industry in Costa Rica.
About Craisa
CRAISA S.A. is a Costa Rican distributor of agricultural, construction, and industrial machinery, founded in 1981 and headquartered in Heredia. It is the official exclusive dealer of CASE IH (agriculture) and CASE Construction Equipment in Costa Rica, covering the entire country through branches in Heredia, San Carlos, Guápiles, and Cartago. The company also distributes specialty brands including Antonio Carraro (Italian specialty tractors), Hangcha (forklifts), XAG agricultural drones, and precision farming systems (Raven/Trimble), while offering in-house service workshops, genuine parts supply, and equipment financing. It employs around 43 people with a highly loyal management core (many directors with 15–22 years of tenure), operates under SAP Business One, and holds official "Carbono Neutral" certification from the Costa Rican government.
Source record: ransomware.live
About the Thegentlemen group
The Gentlemen is a RaaS group that emerged in July–August 2025, rapidly claiming over 320 victims across 17+ countries by offering affiliates a 90% revenue share, deploying a Go-based locker against Windows, Linux, NAS, and BSD systems; a compromised C2 server in 2026 revealed more than 1,570 linked victims. Thegentlemen has listed 835 victims since February 2023.
How Thegentlemen is documented to operate
Valid Accounts
T1078
Stealth
Persistence
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network.
Mitigations:
Application Developer Guidance, User Training, Password Policies, User Account Management, Privileged Account Management, Multi-factor Authentication
MITRE ATT&CK reference →
External Remote Services
T1133
Persistence
Initial Access
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally. Access to Valid Accounts to use the service is often a requirement, which could be obtained through credential pharming or by obtaining the credentials from users after compromising the enterprise network.
Mitigations:
Limit Access to Resource Over Network, Restrict Web-Based Content, Network Segmentation, Multi-factor Authentication, Disable or Remove Feature or Program
MITRE ATT&CK reference →
Exploit Public-Facing Application
T1190
Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration. Exploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets. On ESXi infrastructure, adversaries may exploit exposed OpenSLP services; they may alternatively exploit exposed VMware vCenter servers.
Mitigations:
Vulnerability Scanning, Limit Access to Resource Over Network, Filter Network Traffic, Network Segmentation, Privileged Account Management, Application Isolation and Sandboxing
MITRE ATT&CK reference →
Phishing
T1566
Initial Access
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns. Adversaries may send victims emails containing malicious attachments or links, typically to execute malicious code on victim systems. Phishing may also be conducted via third-party services, like social media platforms.
Mitigations:
Network Intrusion Prevention, Restrict Web-Based Content, User Training, Antivirus/Antimalware, Software Configuration, Audit
MITRE ATT&CK reference →
Windows Management Instrumentation
T1047
Execution
Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems. WMI is an administration feature that provides a uniform environment to access Windows system components. The WMI service enables both local and remote access, though the latter is facilitated by Remote Services such as Distributed Component Object Model and Windows Remote Management. Remote WMI over DCOM operates using port 135, whereas WMI over WinRM operates over port 5985 when using HTTP and 5986 for HTTPS.
Mitigations:
Execution Prevention, Behavior Prevention on Endpoint, User Account Management, Privileged Account Management
MITRE ATT&CK reference →
MITRE ATT&CK techniques attributed to Thegentlemen across its recorded activity, not a finding about how Craisa was reached.
Vulnerabilities Thegentlemen is recorded exploiting
6 of these 6 are in the CISA Known Exploited Vulnerabilities catalog, 4 of them recorded by CISA as used in ransomware campaigns. CVEs attributed to Thegentlemen across its reported activity. There is no indication that any of these was involved in the Craisa incident — the source data does not record an entry point.