The Gentlemen is a rapidly growing ransomware-as-a-service (RaaS) operation that emerged around mid-to-late 2025 and became one of the most active ransomware groups in 2026. It is commonly referenced as Gentlemen or The Gentlemen, with reporting also using variants such as gentleman, gentleman_group, gentlemen_ransomware_group, and gentlemen_raas_affiliates. The group is financially motivated and operates a double-extortion model, encrypting victim environments while also stealing data for extortion and public leak-site pressure. The operation has been linked to a structured affiliate program and aggressive recruitment, with reporting indicating a high affiliate revenue share and a relatively mature internal organization. Leaked internal backend data and partial internal chats exposed details about its administration, affiliate ecosystem, victim handling, negotiation practices, tooling distribution, and intrusion workflows. Those leaks strongly tied the administrator alias zeta88 to management of the platform and infrastructure, and multiple reports assess zeta88 as likely the same individual as hastalamuerte. Reporting has also linked the group’s leadership or operators to prior affiliate activity associated with other major ransomware ecosystems, especially Qilin, and more broadly to experience across operations such as Embargo, LockBit, Medusa, and BlackLock. The Gentlemen is notable for centrally developing, maintaining, and distributing a standardized suite of endpoint security disabling tools to affiliates, a practice that distinguishes it from many other RaaS programs. Its in-house framework, often referred to as GentleKiller, includes multiple variants that abuse vulnerable or malicious drivers in bring-your-own-vulnerable-driver (BYOVD) attacks to terminate or disable EDR and antivirus products at kernel level. The framework has been observed using consistent defense-evasion tradecraft, including packing, fake vendor-themed presentation, fabricated version metadata, copied invalid signatures, and icons intended to impersonate legitimate security software. The group has also operationalized externally sourced EDR-killing tools alongside its own framework and has shown the ability to adopt newly disclosed proof-of-concept BYOVD tooling within days. Intrusion tradecraft associated with The Gentlemen is human-operated and focused heavily on exposed edge infrastructure and credential-based access. Reporting indicates frequent targeting of internet-facing appliances and VPN or security gateway products, particularly Fortinet and Cisco environments, with broader observations also tying the group to exploitation of vulnerabilities in products from SonicWall, Citrix, and Check Point. The group has been associated with brute force activity, exploitation of known vulnerabilities, purchased access from brokers, NTLM relay workflows, and post-compromise use of administrative and offensive tooling for reconnaissance, credential access, privilege escalation, lateral movement, and defense evasion. Leaked chats show active interest in vulnerability tracking and exploitation workflows, including CVE-2024-55591, CVE-2025-32433, and CVE-2025-33073. The group’s tooling ecosystem has included a Go-based encryptor for Windows and Linux environments and an ESXi-focused encryptor written in C, reflecting capability against both enterprise endpoints and virtualization infrastructure. Reporting also links affiliates to additional credential theft tooling, including OxideHarvest, though that stealer has been attributed to an affiliate rather than to the core operators. Internal and external reporting describes The Gentlemen as providing affiliates with a well-packaged intrusion kit that lowers the barrier to entry for less mature operators. Victimology is globally distributed rather than overwhelmingly US-centric. The group has targeted organizations across Southeast Asia, South America, Western Europe, North America, and elsewhere, with observed victims spanning manufacturing, professional services, financial services, technology, telecommunications, retail, and energy. Public reporting in 2026 repeatedly ranked The Gentlemen among the top ransomware groups by victim volume, often second only to Qilin and in some datasets surpassing it for the quarter. Multiple assessments describe the group as one of the most prolific and fastest-scaling ransomware operations of 2026. The Gentlemen’s leaked internal data also revealed structured negotiation tactics, direct administrator involvement in some intrusions, and a relatively small but organized operator set coordinating campaigns, tooling, infrastructure, and payouts. Reporting indicates the group has reused stolen data across campaigns to increase pressure on downstream victims and has combined centralized victim selection with affiliate-driven operations. Overall, The Gentlemen is best characterized as a technically agile, affiliate-enabled ransomware enterprise with strong emphasis on defense evasion, edge-device exploitation, and scalable operational support for affiliates.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 malware families attributed to this actor across reporting.
8 additional families tracked in Mallory.
10 CVEs this actor has used in observed campaigns. 10 of them exploited in the wild.
Recommendations Initial Access: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2024-55591 (Fortinet's FortiOS and FortiProxy)
Recommendations Initial Access: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-33073 (Windows SMB Client)
Recommendations Initial Access: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-32433 (Erlang/OTP SSH server)
NetLogon CVE-2020-1472 ("ZeroLogon") TheGentlemen
Local Security Authority (LSA) CVE-2021-36942 ("PetitPotam") TheGentlemen
5 more CVEs tied to this actor tracked in Mallory.
221 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against Advanced Marketing in Mexico.
Conducting a ransomware attack against European Design.
Conducting a ransomware attack resulting in a data breach against MK Jewelry.
Conducting a ransomware attack against GUERREIROS seguros, a Portugal-based insurance mediation company in the financial services sector.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.