Storm-2697 is a financially motivated cybercriminal threat actor tracked as the operator of The Gentlemen ransomware-as-a-service (RaaS) platform. The group emerged around mid-2025 as a closed ransomware operation and later expanded into a public affiliate-based ecosystem. It has been associated with affiliate recruitment through criminal forums, including outreach to penetration testers and initial access brokers, indicating an organized division between core operators and intrusion partners. Storm-2697 conducts double-extortion ransomware operations, combining data encryption with data theft and threats of public disclosure to pressure victims into payment. Victimology has included organizations in education, transportation, healthcare, and finance, with observed activity spanning North America, South America, Europe, Africa, and Asia. The actor primarily targets Windows enterprise environments. The group’s ransomware tooling, known as The Gentlemen, is written in Go and uses obfuscation. It is notable for unusually aggressive, worm-like lateral movement in addition to standard ransomware functionality. The malware supports broad operator control through command-line options, can elevate privileges, disable security protections, delete shadow copies, clear event logs, remove forensic artifacts, terminate backup, database, virtualization, email, and security-related processes and services, and establish persistence. It also enumerates local and network-accessible storage for encryption and can alter system settings to improve visibility into reachable network resources. A distinguishing characteristic of Storm-2697 operations is automated propagation across Windows networks. The ransomware can transform an infected host into a distribution point and attempt lateral movement through multiple parallel remote execution mechanisms, including PsExec, WMI, scheduled tasks, service creation, SMB-based copy-and-execute workflows, and PowerShell remoting. This multi-path propagation model increases resilience against partial defensive controls and can accelerate enterprise-wide impact. For encryption, The Gentlemen uses a hybrid scheme based on Curve25519 and XChaCha20, including partial encryption of large files to improve speed. The malware can also overwrite free disk space and self-delete after execution, reflecting anti-forensic and destructive tradecraft beyond basic file encryption. Overall, Storm-2697 represents a mature RaaS operator whose combination of affiliate enablement, double extortion, defense evasion, and worm-like spread makes it a high-impact ransomware threat.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
55 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
The group actively tracks and evaluates modern vulnerabilities, including CVE-2024-55591, CVE-2025-32433, and CVE-2025-33073, and combines them with technique-driven paths like backup and management-controller abuse and NTLM relay workflows, giving them a flexible exploitation pipeline.
The group actively tracks and evaluates modern vulnerabilities, including CVE-2024-55591, CVE-2025-32433, and CVE-2025-33073, and combines them with technique-driven paths like backup and management-controller abuse and NTLM relay workflows, giving them a flexible exploitation pipeline.
The group actively tracks and evaluates modern vulnerabilities, including CVE-2024-55591, CVE-2025-32433, and CVE-2025-33073, and combines them with technique-driven paths like backup and management-controller abuse and NTLM relay workflows, giving them a flexible exploitation pipeline.
Defense Evasion. BYOVD через ThrottleStop.sys (CVE-2025-7771, CVSS 8.7)... Легитимный драйвер ThrottleStop.sys ... экспонирует два IOCTL-интерфейса для произвольного чтения и записи в физическую память через MmMapIoSpace... Публичный эксплойт: EDB-52512.
41 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.