The Gentlemen is a human-operated ransomware-as-a-service operation active since at least mid-2025 and tracked by Microsoft as Storm-2697. Reporting widely links it to former Qilin affiliate activity, including the ArmCorp cluster, and describes a small but organized core team supporting affiliates with tooling, negotiation infrastructure, and intrusion guidance. The operation has rapidly become one of the most active ransomware brands by published victim volume and has targeted organizations across multiple regions and sectors, including manufacturing, healthcare, finance, transportation, education, technology, business services, and other enterprise environments.
The malware is best known for a Go-based encryptor for Windows and additional cross-platform lockers associated with Linux and ESXi environments. Its Windows variant uses strong hybrid cryptography based on per-file Curve25519 key exchange and XChaCha20 encryption, supports partial encryption of large files for speed, drops ransom notes, can alter the desktop wallpaper, and is commonly protected by a required execution password that hinders casual analysis and automated detonation. The operation uses double extortion, combining file encryption with theft of sensitive data and leak-site pressure.
A distinguishing feature of The Gentlemen is aggressive self-propagation and lateral movement. The ransomware can turn an infected Windows host into a distribution point, expose a hidden SMB share, and attempt remote execution across reachable systems using multiple techniques including PsExec, WMI, scheduled tasks, services, PowerShell remoting, administrative shares, WinRM, and Group Policy-based deployment. This worm-like behavior enables rapid domain-wide impact from a limited initial foothold.
The operation is also notable for mature defense-evasion tradecraft. Observed behavior includes disabling or weakening Microsoft Defender, adding exclusions, deleting shadow copies, clearing Windows event logs, removing forensic artifacts, terminating backup, database, virtualization, and security processes, and establishing persistence through scheduled tasks and autorun mechanisms. Multiple reports associate the group with custom EDR-killing tooling, including BYOVD-based approaches and environment-specific attempts to terminate protected security products before encryption.
Initial access is most strongly associated with exploitation of internet-facing edge infrastructure and credential abuse rather than phishing-led delivery. Reported access vectors include vulnerable VPN and firewall appliances, brute force and credential spraying, stolen or leaked credentials, NTLM relay workflows, compromised remote services, and cooperation with initial access brokers. Public reporting also links the operation to active interest in vulnerabilities affecting Fortinet, Cisco or Erlang-based SSH services, Windows SMB, and virtualization infrastructure.
Beyond the encryptor itself, The Gentlemen intrusions have been associated with reconnaissance, credential theft, exfiltration tooling, and post-exploitation frameworks used to expand access and prepare enterprise-wide deployment. The group has also recruited affiliates aggressively on criminal forums, offering unusually favorable revenue sharing and packaged intrusion support. Overall, The Gentlemen represents a fast-scaling, affiliate-enabled ransomware threat that combines strong encryption, broad platform coverage, rapid lateral spread, and robust defense evasion to maximize operational disruption and extortion leverage.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2025-33073 – NTLM reflection / NTLM relay qbit references RelayKing and shares output showing domains being scanned for NTLM relay issues, including checks that explicitly cover CVE-2025-33073. This is strong evidence that they are not just reading about the vulnerability but have integrated RelayKing into their standard reconnaissance process. | The Gentlemen ransomware-as-a-service (RaaS) operation is a relatively new group that emerged around mid-2025... The leaked Rocket backend and internal chats show that this scale is driven not by a loose crowd, but by a small, tightly coordinated core...
The group’s active tracking and evaluation of modern CVEs such as CVE-2024-55591, CVE-2025-32433, and CVE-2025-33073 . ... CVE-2024-55591 – FortiOS management interface This vulnerability affects the FortiOS management interface and fits directly into their broader focus on Fortinet appliances as high-value initial access points. | The Gentlemen ransomware-as-a-service (RaaS) operation is a relatively new group that emerged around mid-2025... The leaked Rocket backend and internal chats show that this scale is driven not by a loose crowd, but by a small, tightly coordinated core...
CVE-2025-32433 – Erlang SSH vulnerability (Cisco context) In the logs, qbit shares a proof-of-concept (PoC) for CVE-2025-32433, and zeta88 comments on its quality and applicability. This shows that the group is not simply aware of the CVE but is actively evaluating whether it can be used in real operations, specifically in environments where Cisco or Erlang-based SSH services are exposed. | The Gentlemen ransomware-as-a-service (RaaS) operation is a relatively new group that emerged around mid-2025... The leaked Rocket backend and internal chats show that this scale is driven not by a loose crowd, but by a small, tightly coordinated core...
Privilege Escalation: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-7771 ( ThrottleStop.sys driver) | The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS.
Recommendations Initial Access: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-55182 (React2Shell) | The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS.
Common Vulnerabilities Exploited CVE-2023-27532 Veeam Backup & Replication Missing authentication targeted for backup destruction Critical Patching recommended | The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.
Common Vulnerabilities Exploited CVE-2024-37085 VMware ESXi Authentication bypass ESXi locker deployment vector High Patching recommended | The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.
The Gentlemen surfaced as a ransomware operation in September 2025 and by June 13, 2026 had listed 483 victims on their dark-web leak site, 380 of them in 2026 alone.
The Gentlemen surfaced as a ransomware operation in September 2025 and by June 13, 2026 had listed 483 victims on their dark-web leak site, 380 of them in 2026 alone.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS.
The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS.
The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025.
The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.
The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.
This year saw the emergence of The Gentlemen, a prominent example of a group operating under the ransomware-as-a-service (RaaS) model.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware uses WMI via wmic.exe to create remote processes.
When the -- system argument is provided (either directly or via the -- full argument), the malware creates a scheduled task to re-execute itself as SYSTEM.
The scheduled task DefU is set to run the defense evasion blob, UpdateGU executes the payload from the infected host’s SMB share, and UpdateGU2 runs the pre-staged copy from the target’s local C:\Temp directory.
When the -- system argument is provided (either directly or via the -- full argument), the malware creates a scheduled task to re-execute itself as SYSTEM.
The scheduled task DefU is set to run the defense evasion blob, UpdateGU executes the payload from the infected host’s SMB share, and UpdateGU2 runs the pre-staged copy from the target’s local C:\Temp directory.
The commands copy the malware executable into C:\Temp, creates a hidden Server Message Block (SMB) share named share$ pointing to that directory, and modifies registry settings to allow anonymous access.
The malware executes the following command sequence to create three Windows services on the target host.
The GupdateS value under HKEY_LOCAL_MACHINE (HKLM) provides device-wide persistence that allows the malware to run at startup for all users, while the GupdateU value under HKEY_CURRENT_USER (HKCU) provides user-scoped persistence within the current profile.
When the -- system argument is provided (either directly or via the -- full argument), the malware creates a scheduled task to re-execute itself as SYSTEM.
The scheduled task DefU is set to run the defense evasion blob, UpdateGU executes the payload from the infected host’s SMB share, and UpdateGU2 runs the pre-staged copy from the target’s local C:\Temp directory.
Their research shows the ransomware follows a very deliberate sequence, starting with password validation and privilege escalation, then moving into defense evasion, encryption, and finally network-wide spreading.
the custom ransomware locker ... as well as the GPO-based spread mechanism and the locker’s 'spread' module.
The malware executes the following command sequence to create three Windows services on the target host.
The GupdateS value under HKEY_LOCAL_MACHINE (HKLM) provides device-wide persistence that allows the malware to run at startup for all users, while the GupdateU value under HKEY_CURRENT_USER (HKCU) provides user-scoped persistence within the current profile.
To further impede recovery efforts, the malware deletes all Volume Shadow Copies using both vssadmin and wmic... It then clears the System, Application, and Security event logs using wevtutil to remove key audit trails.
After dropping PsExec, the malware attempts to enumerate and discover remote systems on the network, including workstations, servers, and domain controllers.
The -- spread argument accepts either explicit credentials in domain/user:password format for authenticated lateral movement, or an empty string to reuse the current session’s authentication token.
the malware pulls in a legitimate system tool called PsExec... and starts scanning the network for reachable machines, including regular workstations, servers, and domain controllers.
The malware stops a list of running processes using the command: The table below summarizes the different categories and processes being targeted.
The -- spread argument accepts either explicit credentials in domain/user:password format for authenticated lateral movement, or an empty string to reuse the current session’s authentication token.
the custom ransomware locker, the RaaS panel and builder ... as well as the GPO-based spread mechanism and the locker’s 'spread' module.
The malware binary carries an embedded copy of PsExec and drops it to C:\Temp\psexec.exe on the infected device. If the embedded PsExec payload cannot be extracted successfully, the malware falls back to downloading PsExec directly from Microsoft’s Sysinternals Live service.
delete Volume Shadow Copies twice over using two separate commands for reliability. It also clears command history and deletes backup and recovery tools to make restoring systems without paying much harder.
Finally, once the environment is prepared and critical data is in their control, they deploy their custom ransomware 'locker,' which is designed to spread quickly across the network... and encrypt systems in a coordinated manner.
In addition to terminating processes, the malware disables and stops a list of Windows services.
To further impede recovery efforts, the malware deletes all Volume Shadow Copies using both vssadmin and wmic.
Before starting file encryption, the malware executes a sequence of commands to disable defensive controls and remove potential forensic artifacts.
The PowerShell commands disable Microsoft Defender real-time monitoring to remove active protection on the infected device. The malware then adds its own executable to the Defender exclusion list to avoid detection. Finally, it excludes the entire C:\ volume from scanning.
177 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
40 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A rapidly scaling ransomware-as-a-service operation noted for structured negotiation tactics and a dedicated suite of EDR-disabling tools distributed to affiliates.
Ransomware group that rose to the top by victim count in Q2 2026, driven by aggressive affiliate recruitment, pre-packaged intrusion kits, and likely AI-accelerated tooling updates.
A ransomware-as-a-service operation that also functions as an Initial Access Broker, providing affiliates access to pre-exploited FortiGate devices and deploying cross-platform lockers against Windows, Linux, and ESXi environments.
A ransomware-as-a-service operation active since at least July 2025. It uses ransomware variants written in C and Go, employs multiple initial access techniques, and has used custom tooling including a Go-based backdoor and the GentleKiller EDR-killer framework to improve defense evasion and enterprise impact.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.