Skip to main content
Mallory

Gentlemen

Also known asgentlemen

Gentlemen is a ransomware group first identified around August 2025 and described as one of the fastest-growing and most active emerging ransomware threats of 2025. It is referred to as a relatively sophisticated ransomware-as-a-service group in some reporting, while other reporting describes it as a tightly controlled non-affiliate team; high-confidence reporting also states it uses an affiliate model. The group uses double extortion, stealing data before encrypting files, and has been described as Russian-speaking in reporting on attacks affecting Romania. Gentlemen began posting on leak sites in September 2025 and accumulated 408 victims in 246 days. It has maintained a presence on the Rehub forum since September 2025. Gentlemen targets medium and large enterprises globally across at least 17 countries and sectors including healthcare, manufacturing, insurance, construction, and critical infrastructure. Reported victims and claimed targets include Mackay Sugar in Australia, Romania’s Oltenia Energy Complex, and attacks affecting Romanian critical infrastructure more broadly. Initial access and intrusion activity attributed to Gentlemen includes use of compromised credentials, credentials stolen by infostealers, and targeting of Internet-exposed services. Reported tradecraft includes Group Policy modification/manipulation, termination of security and backup services, disabling Windows Defender, stopping services including Veeam, MSSQL, and MongoDB, use of WinSCP for encrypted exfiltration, and use of BYOVD techniques to disable defenses. ESET telemetry confirmed affiliates of Gentlemen used the commercial EDR killer DemoKiller. The ransomware is written in Go and uses anti-analysis and execution controls including a required password argument. It encrypts local drives and network shares, drops README-GENTLEMEN.txt ransom notes, and has been reported to use the .7mtzhh file extension. Encryption behavior described in reporting includes use of X25519 for key exchange and XChaCha20 for file encryption, with selective partial encryption of large files to improve speed. Known alias in the provided content: Gentlemen.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

10 of 15 tactics18 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1078×2
Valid Accounts
TA0003
Persistence
1 technique
T1078×2
Valid Accounts
TA0004
Privilege Escalation
2 techniques
T1078×2
Valid Accounts
T1484
Domain or Tenant Policy Modification
T1484.001
Group Policy Modification
TA0005
Stealth
1 technique
T1078×2
Valid Accounts
TA0112
Defense Impairment
1 technique
T1484
Domain or Tenant Policy Modification
T1484.001
Group Policy Modification
TA0006
Credential Access
2 techniques
T1003
OS Credential Dumping
T1649
Steal or Forge Authentication Certificates
TA0008
Lateral Movement
1 technique
T1021
Remote Services
TA0011
Command and Control
2 techniques
T1090
Proxy
T1105
Ingress Tool Transfer
TA0010
Exfiltration
1 technique
T1041
Exfiltration Over C2 Channel
TA0040
Impact
4 techniques
T1486×5
Data Encrypted for Impact
T1489
Service Stop
T1490
Inhibit System Recovery
T1657
Financial Theft
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping13

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.