Gentlemen is a ransomware-as-a-service (RaaS) operation that emerged in 2025 and became one of the most active ransomware groups in 2026. The group runs a double-extortion model, combining data theft with file encryption and public leak-site pressure, and has been linked to a broad affiliate ecosystem. Reporting has associated the operation with Russian-speaking cybercriminals, and multiple assessments indicate its leadership and early membership drew from affiliates or former members connected to other major ransomware programs including Qilin, Embargo, LockBit, Medusa, and BlackLock. The alias hastalamuerte has been publicly linked to the group’s founder or leader in several investigations. Gentlemen is notable for centralizing capabilities that many other RaaS programs leave to affiliates, especially defense evasion. Its operators develop, maintain, and distribute a standardized suite of endpoint detection and response (EDR) killers to vetted affiliates. The best-known in-house framework, dubbed GentleKiller, includes multiple variants that use bring-your-own-vulnerable-driver techniques to gain kernel-level access and terminate security tooling. Researchers have tied the framework to repeated process-killing loops, impersonation of legitimate security-related software, shared obfuscation patterns, and targeting of hundreds of security-product processes across dozens of vendors. Gentlemen has also been observed operationally integrating additional third-party or externally sourced EDR-killing tools such as HexKiller, ThrottleBlood, and HavocKiller under a common evasion and masquerading layer. The group has shown unusual agility in weaponizing newly disclosed proof-of-concept code related to vulnerable-driver abuse, incorporating fresh techniques into its tooling within days. Its binaries have been observed using packers and masquerading features such as fabricated version metadata, copied or invalid signatures, and vendor-like icons to complicate detection and attribution. This emphasis on pre-encryption security-tool disruption appears to be a core differentiator for the operation and lowers the technical barrier for affiliates. Gentlemen’s ransomware tooling includes a primary cross-platform Go-based encryptor used against Windows, Linux, and other environments, as well as a newer C-based Windows encryptor observed in limited attacks and assessed as still under active development or testing. Separate reporting also describes a C-based ESXi-focused encryptor. In addition to encryption, the group has deployed a custom Go backdoor for persistence, command execution, proxying, and continued internal reconnaissance. Gentlemen-linked activity has also involved credential theft tooling, including the Rust-based stealer OxideHarvest, although some research attributes that tool to a specific affiliate rather than to the core operators. Initial access has been associated with exploitation of vulnerable internet-facing services, VPN gateways, firewalls, and the use of stolen, weak, or default credentials. Some assessments indicate cooperation with access brokers. Post-compromise behavior includes internal reconnaissance, credential and traffic collection, lateral movement via remote administration and domain-wide deployment mechanisms, and attempts to disable defenses before exfiltration and encryption. Victim selection has been reported as centrally influenced by FortiGate configuration or misconfiguration rather than geography alone. Gentlemen targets large enterprises and critical infrastructure organizations across multiple sectors, including manufacturing, construction, information technology, finance, healthcare, logistics, government-related environments, utilities, and energy. Its victimology is globally distributed but is repeatedly described as less US-centric than many peer ransomware operations, with concentrations in Southeast Asia, South America, and Western Europe. Countries repeatedly cited in connection with observed victimization include Brazil, Thailand, France, China, Indonesia, and Taiwan. The operation has also been cited as an example of cybercriminal adoption of artificial intelligence in routine workflows. Members reportedly evaluated mainstream commercial AI models based on operational restrictions and used AI assistance to accelerate internal tool development, including management-platform creation. This reflects a broader pattern of operational maturity rather than a distinct malware family. Known aliases and naming variants are limited, with Gentlemen and The Gentlemen both used in public reporting. No high-confidence evidence in the available information supports treating these as separate groups.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
42 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
27 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operations incorporating AI into routine criminal workflows, including evaluating commercial AI models for weaker guardrails and using AI to rapidly build internal tooling.
Ransomware operators using AI to compare commercial models, evade guardrails, and rapidly build internal tooling for criminal operations.
RaaS-группа, активная с середины 2025 года и заметно усилившаяся в начале 2026 года; проводит вымогательские атаки против крупных компаний и объектов критической инфраструктуры по всему миру, тестирует новый Windows-шифровальщик на C наряду с основным кросс-платформенным Go-шифровальщиком.
Ransomware group listed as the most active this week by number of claimed victims, with 24 extortion claims.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.