ArmCorp was a ransomware affiliate operation in the Qilin ransomware ecosystem. It was administered by the operator known as hastalamuerte, assessed to be the same person using the zeta88 handle. In July 2025, ArmCorp publicly disputed alleged unpaid affiliate commissions with Qilin’s operators and subsequently separated from the service. The split is assessed to have led to the formation of The Gentlemen ransomware-as-a-service operation under hastalamuerte/zeta88, while another former participant, Devman, formed a separate operation. ArmCorp is therefore principally notable as the predecessor affiliate group from which The Gentlemen emerged.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A former Qilin affiliate group and direct precursor to The Gentlemen. Internal disputes with Qilin appear to have caused ArmCorp members to divide into competing ransomware operations, including The Gentlemen and Devman's separate RaaS effort.
Named as the prior Qilin affiliate identity of The Gentlemen's founders before they split and formed The Gentlemen.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.