Tool
Penelope
- First Reported
- Oct 5, 2026
- Latest Reported
- Oct 5, 2026
Reported Context (1)
- the operation. Port 9999 ran the HTTP upload listener receiving stolen data from victim networks. Penelope reverse shell sessions were handled here alongside the MCP C2 tooling. CloudSEK Finds Gentlemen Ransomware Affiliate’s Exposed Servers and Stolen Data
Threat Actors (2)
MITRE ATT&CK (11)
Products (12)
Tools (23)
Industries (6)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.