The Gentlemen is a rapidly growing ransomware-as-a-service (RaaS) operation active since at least mid-2025 and tracked by Microsoft as Storm-2697. Multiple reports assess that it emerged from the Qilin ecosystem after a split involving operators previously associated with the ArmCorp affiliate. The group has become one of the most active ransomware actors of 2026 by victim volume and leak-site activity. The operation uses a double-extortion model, combining data theft with file encryption, and targets organizations across numerous sectors and regions. Reported victimology includes manufacturing, healthcare, financial services, technology, logistics, government, education, business services, and critical infrastructure. Geographic targeting appears broad, with notable activity reported across Europe, Southeast Asia, South America, Australia, and North America. Some reporting indicates the group avoids targeting Commonwealth of Independent States countries. The Gentlemen is notable for centrally equipping affiliates with standardized defense-evasion tooling rather than leaving such development to individual operators. Its in-house GentleKiller framework is a bring-your-own-vulnerable-driver (BYOVD) EDR/AV killer suite with multiple variants that impersonate legitimate software and abuse signed vulnerable or malicious kernel drivers to terminate security products at scale. Reporting also links the group to additional security-disabling tools including HexKiller, ThrottleBlood, HavocKiller, and custom tooling incorporating PoisonX. The group has been observed rapidly operationalizing newly disclosed BYOVD techniques and, in at least one documented case, abusing a vulnerable Kontron driver to obtain kernel-level code execution and terminate protected security processes. Initial access commonly relies on exploitation of internet-facing edge infrastructure and valid credentials rather than phishing as the primary vector. Reported access methods include exploitation of firewalls, VPN appliances, public-facing services, brute force, stolen or leaked credentials, and cooperation with initial access brokers. Post-compromise activity includes Active Directory reconnaissance, credential theft, network discovery, packet capture, lateral movement with administrative tooling, abuse of Group Policy and shared domain resources for broad deployment, and encrypted data exfiltration prior to ransomware execution. The malware ecosystem associated with The Gentlemen includes mature Go-based ransomware and additional C-based variants. The encryptors are reported to support cross-platform targeting, including Windows, Linux, ESXi, NAS, and BSD environments. Observed tradecraft includes process and service termination, shadow copy deletion, event log clearing, persistence via scheduled tasks and autoruns, ACL manipulation, self-deletion, and in some cases worm-like or self-propagating lateral movement. The group also uses custom backdoors and common remote administration or post-exploitation tooling to maintain access and coordinate operations. The Gentlemen recruits affiliates on major cybercrime forums and has been reported to offer unusually favorable revenue sharing to affiliates. A significant internal leak in May 2026 exposed chats, victim data, negotiations, payouts, and tooling details, providing unusual visibility into the group’s organization and affiliate support model. Reporting also indicates the operators have used mainstream large language models such as ChatGPT, Gemini, and Claude to assist development and operations. Known aliases and tracking names include Storm-2697. The group is widely assessed as a sophisticated criminal enterprise rather than a state-sponsored actor, though its scale, tooling maturity, and operational tempo place it among the most consequential ransomware threats observed in 2026.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
60 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
Recommendations Initial Access: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2024-55591 (Fortinet's FortiOS and FortiProxy ...)
Recommendations Initial Access: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-33073 (Windows SMB Client)
Recommendations Initial Access: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-32433 (Erlang/OTP SSH server ...)
Privilege Escalation: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-7771 (ThrottleStop.sys driver)
Operators scanned for and exploited internet-facing vulnerabilities including the FortiOS authentication-bypass flaw CVE-2024-55591, alongside older Active Directory weaknesses like ZeroLogon and PetitPotam.
2 more CVEs tied to this actor tracked in Mallory.
221 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A rapidly emerging ransomware operator that became the most active ransomware group globally in the reporting period, using advanced tooling and proxy infrastructure to accelerate attacks and operating stealthily within compromised networks.
A rapidly growing RaaS operation active since at least July 2025, likely evolving from a Qilin affiliate into its own RaaS model around September 2025. It uses multi-platform ransomware written in C and Go, custom tooling including a Go-based backdoor and the GentleKiller EDR killer, and relies on multiple initial access methods such as edge-device exploitation, brute force, stolen credentials, and collaboration with initial access brokers.
Used the vulnerable ktapi.sys driver in an EDR-killer exploit to gain kernel code execution and terminate security processes.
Ransomware group noted as a close second to Qilin in confirmed 2026 victims.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.