The Gentlemen is a human-operated ransomware-as-a-service operation, also tracked by Microsoft as Storm-2697, that emerged in mid-2025 and rapidly became one of the most active ransomware brands globally. It is widely assessed as having roots in the Qilin ecosystem, with reporting linking its operators to the former ArmCorp affiliate crew and to the Russian-speaking actor known as hastalamuerte or zeta88. The operation follows a double-extortion model, combining data theft with multi-platform encryption and public leak-site pressure, and has recruited affiliates through major cybercrime forums while offering unusually favorable revenue sharing.
The malware associated with The Gentlemen is notable for cross-platform support and aggressive propagation. Its primary Windows encryptor is written in Go and obfuscated, while additional variants have been reported for Linux, NAS, BSD, and ESXi, including a C-based ESXi locker and an emerging Windows-focused C variant. The ransomware uses hybrid public-key and symmetric cryptography based on Curve25519 or X25519 with XChaCha20, supports partial encryption of large files for speed, and commonly drops a ransom note after encryption. Some builds require a password at launch, which appears intended to hinder sandboxing and unauthorized execution.
A distinguishing feature of The Gentlemen is its worm-like lateral movement capability. When configured for spreading, the ransomware can stage itself over SMB, enumerate reachable systems, and attempt numerous remote execution methods per target, including PsExec, scheduled tasks, services, WMI, WinRM, and PowerShell-based techniques. The group has also been observed abusing Group Policy and the NETLOGON share for domain-wide deployment. This propagation model enables rapid expansion from a single foothold to broad enterprise impact.
The operation places heavy emphasis on defense evasion and post-compromise control. Before encryption, The Gentlemen commonly disables or tampers with Microsoft Defender and other security controls, deletes shadow copies, clears Windows event logs, removes forensic artifacts, stops backup, database, virtualization, and security-related processes and services, and may establish persistence through scheduled tasks and registry autoruns. Multiple reports describe the group using bring-your-own-vulnerable-driver techniques and dedicated EDR-killing frameworks, including GentleKiller and other security-process termination tools, to neutralize endpoint protections. Associated intrusions have also involved custom backdoors, proxy malware, remote administration tools, and commodity post-exploitation frameworks.
Initial access is most strongly associated with exploitation of internet-facing edge infrastructure and credential abuse rather than phishing as a primary vector. The group has repeatedly been linked to attacks against VPNs, firewalls, and other exposed services, including exploitation of known vulnerabilities, brute-force activity, use of stolen or leaked credentials, and cooperation with initial access brokers. Once inside, affiliates conduct Active Directory reconnaissance, credential theft, privilege escalation, lateral movement, and data exfiltration before deploying the locker.
Victimology indicates broad global targeting across dozens of countries, with recurring impact in manufacturing, healthcare, financial services, technology, transportation, business services, and other enterprise sectors. The operation is generally described as avoiding organizations in Russia and other CIS countries, consistent with common restrictions among Russian-speaking ransomware programs. The Gentlemen’s rapid growth, mature affiliate support, cross-platform tooling, and integrated propagation and defense-evasion capabilities make it a high-tempo ransomware threat capable of causing large-scale enterprise disruption.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025.
The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025.
The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025.
The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025.
The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025.
Common Vulnerabilities Exploited CVE-2023-27532 Veeam Backup & Replication Missing authentication targeted for backup destruction Critical Patching recommended | The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.
Common Vulnerabilities Exploited CVE-2024-37085 VMware ESXi Authentication bypass ESXi locker deployment vector High Patching recommended | The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.
The Gentlemen surfaced as a ransomware operation in September 2025 and by June 13, 2026 had listed 483 victims on their dark-web leak site, 380 of them in 2026 alone.
The Gentlemen surfaced as a ransomware operation in September 2025 and by June 13, 2026 had listed 483 victims on their dark-web leak site, 380 of them in 2026 alone.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025.
The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.
The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.
This year saw the emergence of The Gentlemen, a prominent example of a group operating under the ransomware-as-a-service (RaaS) model.
In an analysis of the ransomware in late last year, LevelBlue's Cybereason team described The Gentlemen as a "highly adaptive, fast-moving ransomware operation" that combines mature ransomware techniques with RaaS features, double extortion, cross-platform lockers, and flexible propagation, and affiliate support.
The Gentlemen за неполный год из осколка Qilin превратился во второго по активности RaaS-оператора в мире. Microsoft Threat Intelligence ведёт их инфраструктуру как Storm-2697.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware uses WMI via wmic.exe to create remote processes... The first command executes the defense evasion blob, the second runs the payload from the infected host’s SMB share, and the third runs the pre-staged copy from the target’s local C:\Temp directory.
To get the payload running, the malware tries as many as 21 different remote execution methods per target, including remote file copying, PsExec, scheduled tasks, Windows services, and PowerShell based techniques.
When the -- system argument is provided... the malware creates a scheduled task to re-execute itself as SYSTEM... The encryptor can establish persistence for itself through two mechanisms: scheduled tasks and registry keys.
This is complemented by the use of Cobalt Strike, Mimikatz, and domain-wide propagation via GPO, indicating a tightly coordinated, human-operated attack workflow...
To get the payload running, the malware tries as many as 21 different remote execution methods per target, including remote file copying, PsExec, scheduled tasks, Windows services, and PowerShell based techniques.
When the -- system argument is provided... the malware creates a scheduled task to re-execute itself as SYSTEM... The encryptor can establish persistence for itself through two mechanisms: scheduled tasks and registry keys.
To get the payload running, the malware tries as many as 21 different remote execution methods per target, including remote file copying, PsExec, scheduled tasks, Windows services, and PowerShell based techniques.
When the -- system argument is provided... the malware creates a scheduled task to re-execute itself as SYSTEM... The encryptor can establish persistence for itself through two mechanisms: scheduled tasks and registry keys.
Before touching a single file, the ransomware works to disable Microsoft Defender, wipe forensic logs... It also clears command history
In addition to terminating processes, the malware disables and stops a list of Windows services using the commands...
After dropping PsExec, the malware attempts to enumerate and discover remote systems on the network, including workstations, servers, and domain controllers. Each discovered host becomes a candidate target for propagation.
The -- spread argument accepts either explicit credentials in domain/user:password format for authenticated lateral movement, or an empty string to reuse the current session’s authentication token.
the malware pulls in a legitimate system tool called PsExec... and starts scanning the network for reachable machines, including regular workstations, servers, and domain controllers.
The malware stops a list of running processes using the command... The table below summarizes the different categories and processes being targeted.
The malware can only perform this task if it’s executed from an account with administrator privilege.
To get the payload running, the malware tries as many as 21 different remote execution methods per target, including remote file copying, PsExec, scheduled tasks, Windows services, and PowerShell based techniques.
publishing it over a hidden network share configured for anonymous access... re-enabling an outdated and insecure version of the file sharing protocol.
delete Volume Shadow Copies twice over using two separate commands for reliability. It also clears command history and deletes backup and recovery tools to make restoring systems without paying much harder.
For the actual encryption, the malware uses a hybrid approach pairing Curve25519 elliptic curve cryptography with the XChaCha20 stream cipher, generating a unique key for every single file it touches.
In addition to terminating processes, the malware disables and stops a list of Windows services... backup, storage, and recovery software... EDR... Microsoft Exchange...
Against each target, the malware first runs a script that weakens the remote machine’s defenses, disabling security monitoring, turning off firewall protection... Before touching a single file, the ransomware works to disable Microsoft Defender
Defense evasion: Microsoft Defender disabled, exclusions added, Security event log cleared ... On the backup server they disabled Microsoft Defender real time protection at 20:51 UTC ... Every time the payload ran it ... added Microsoft Defender process and path exclusions.
177 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
37 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware-as-a-service operation active since at least July 2025. The operators reportedly evolved from an affiliate of Qilin, use ransomware variants written in C and Go, and employ custom tooling including a Go-based backdoor and the GentleKiller EDR-killer framework to support intrusion, defense evasion, and encryption across different environments.
Mentioned only in passing as related reading about ransomware cleanup, not as part of the primary malware discussed.
A human-operated ransomware-as-a-service operation using a Go-based cross-platform encryptor with self-propagation, double extortion, data exfiltration, and extensive defense evasion including BYOVD-based EDR/AV killing.
A Go-based ransomware family that uses strong hybrid encryption, double extortion, and a self-propagation mechanism to spread laterally across networks. It abuses PsExec and multiple remote execution techniques, disables defenses, deletes shadow copies and logs, and can operate as a ransomware-as-a-service offering.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.