Skip to main content
Mallory
Back to intelligence
ransomware-group-operationcybercrime-service-ecosystemunderground-data-leakdata-exfiltration-method

Emergence and Operations of The Gentlemen Ransomware-as-a-Service Group

Updated 2d agoFirst seen Nov 20, 202522 sources

The Gentlemen ransomware group has rapidly established itself as a significant threat actor since its emergence around July 2025, leveraging a Ransomware-as-a-Service (RaaS) model and advanced dual-extortion tactics. The group has claimed at least 48 victims within a three-month period, utilizing the XChaCha20 encryption algorithm to lock files and exfiltrating sensitive business data to pressure organizations into paying ransoms. Their operations are characterized by a combination of established ransomware techniques and innovative strategies, including the development of their own RaaS platform after experimenting with various affiliate models, which has enabled them to quickly adapt to new attack vectors and maintain persistence against targeted organizations.

Threat intelligence reports highlight that The Gentlemen's data leak site is active, and the group has demonstrated a willingness to publish stolen data if ransom demands are not met. Their evolution from testing other ransomware platforms to building a proprietary service underscores their technical sophistication and intent to scale operations. Security professionals are advised to monitor for indicators of compromise related to The Gentlemen and to ensure robust data protection and incident response measures are in place to mitigate the risk posed by this rapidly evolving ransomware group.

Share:
Emergence and Operations of The Gentlemen Ransomware-as-a-Service Group
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

15 events from the most recent confirmed update back to the earliest known activity.

15 EVENTS
Jun 5, 20263d ago

Complexul Energetic Oltenia reported as Gentlemen ransomware victim

The reference says The Gentlemen ransomware group carried out a ransomware attack on Romanian state energy operator Complexul Energetic Oltenia, adding a newly disclosed victim to the campaign. The article presents this as part of the group's documented incident activity in 2026.

The Gentlemen Ransomware: Threat Profile | by privacyinsightsolutions.com | May, 2026 | OSINT Team
May 28, 202611d ago

Microsoft publishes analysis of The Gentlemen's self-propagating Go encryptor

On 2026-05-28, Microsoft published research on The Gentlemen ransomware, which it tracks as Storm-2697, detailing the malware's Go-based encryptor, hybrid Curve25519 and XChaCha20 encryption, and aggressive self-propagation across Windows networks using multiple lateral movement methods. The report also provided detections, hunting guidance, and mitigations including Defender protections, attack surface reduction rules, and EDR controls.

The Gentlemen ransomware: Dissecting a self-propagating Go encryptor | Microsoft Security Blog
May 27, 202612d ago

NTT says The Gentlemen accounts for 10% of ransomware attacks

NTT reported that The Gentlemen had become one of the most active ransomware operators, accounting for 10% of observed attacks and ranking second only to Qilin. The report said the group primarily targeted industrial and IT organizations, focused heavily on Europe including the UK and Germany, and named victims including Synergy France, UK Electronics, and Equity Life.

New ransomware threat group, The Gentlemen, has become one of the most active ransomware operators, accounting for 10% of all attacks | IT Pro
May 21, 202618d ago

Huntress details Gentlemen defense-evasion tactics from two incidents

On 2026-05-21, Huntress published analysis of two post-incident The Gentlemen ransomware deployments affecting a shipping and transportation organization and a construction company. The report documented defense-evasion and execution tradecraft including scheduled tasks, PowerShell-based Microsoft Defender tampering, selective clearing of Windows logs, use of a SOCKS proxy beaconing to 193.233.202[.]17, and redeployment of the encryptor from a NETLOGON share after initial execution was blocked.

The Gentleman Ransomware | Defense Evasion TTPs Uncovered | Huntress
May 18, 202621d ago

LevelBlue links The Gentlemen to Qilin affiliate lineage

On 2026-05-18, LevelBlue assessed that The Gentlemen was likely not a wholly new operation but a continuation or reorganization of prior affiliate activity associated with the Qilin ecosystem and the Russian-speaking actor "hastalamuerte." This represented a new attribution and lineage assessment for the ransomware group.

A Closer Look at The Gentlemen’s Alleged Leak
May 11, 202628d ago

Data leak exposes The Gentlemen's internal operations

By 2026-05-11, stolen data from The Gentlemen ransomware group had been offered for sale on Breached and then released publicly, exposing internal chats, victim information, operational data, and a bitcoin wallet address. Analysis of the leak revealed details about the group's infrastructure management, targeting, OPSEC, use of compromised Fortinet credentials, and enterprise-focused intrusion tactics.

Tables Turned: Gentlemen Ransomware Group Suffers Data Leak
May 10, 202629d ago

The Gentlemen claims 352 attacks across more than 70 countries

By 2026-05-10, The Gentlemen had publicly claimed 352 attacks in the first half of 2026, indicating continued growth beyond the previously reported 320-plus victims. The reported victims spanned more than 70 countries, with heavy impact on professional services, manufacturing, technology, and healthcare.

The Gentlemen Ransomware Attacks Windows, Linux, NAS, BSD, and ESXi Attacks
May 4, 20261mo ago

The Gentlemen administrator acknowledges internal leak

On 2026-05-04, the administrator of The Gentlemen ransomware operation reportedly acknowledged that the group’s internal Rocket backend and chats had been leaked. The acknowledgment preceded the broader public release and analysis of the stolen data that exposed the group’s structure, tooling, affiliates, and negotiations.

Thus Spoke…The Gentlemen - Check Point Research
Apr 20, 20262mo ago

Check Point links Gentlemen affiliate attack to SystemBC botnet

While investigating a Gentlemen ransomware affiliate intrusion, Check Point identified a SystemBC proxy malware botnet with more than 1,570 infected hosts, largely affecting corporate and organizational environments. The researchers also disclosed new intrusion details and published indicators of compromise and a YARA rule for related activity.

The Gentlemen ransomware now uses SystemBC for bot-powered attacks

The Gentlemen surpasses 320 claimed victims

Check Point Research reported that The Gentlemen had publicly claimed more than 320 victims, with most of the growth occurring in early 2026. The report characterized the group as a rapidly expanding ransomware-as-a-service operation with a broad, enterprise-focused intrusion ecosystem.

DFIR Report - The Gentlemen & SystemBC: A Sneak Peek Behind the Proxy - Check Point Research
Mar 19, 20263mo ago

Group-IB links The Gentlemen to Qilin dispute and exposes operations

On 2026-03-19, Group-IB published research saying The Gentlemen emerged from a dispute within the Qilin ecosystem and was exposed in part by affiliate 'hastalamuerte.' The report detailed the group's use of FortiGate VPN access, automated lateral movement, credential theft, backup disruption, anti-forensics, and BYOVD-based defense evasion across Windows, Linux, and ESXi targets.

Ransomware Affiliate Exposes Details of 'The Gentlemen' Operation - Infosecurity Magazine
Nov 20, 20257mo ago

The Gentlemen reaches 48 reported victims in three months

By November 2025, reporting said the operation had accumulated 48 victims over roughly a three-month period, indicating rapid growth of the campaign.

Nov 18, 20257mo ago

Cybereason publishes technical analysis and IOCs

Cybereason released a detailed analysis of The Gentlemen’s Windows, Linux, and ESXi ransomware variants, describing persistence, lateral movement, defense evasion, encryption methods, and providing indicators of compromise and MITRE ATT&CK mappings.

Sep 1, 20259mo ago

The Gentlemen begins publishing victims on leak site

The group rapidly started naming victims on its dark web leak site during September and October 2025, marking the public operational phase of its dual-extortion campaign.

Jul 1, 202511mo ago

The Gentlemen ransomware group emerges

Cybereason assessed that the ransomware group known as “The Gentlemen” emerged around July 2025 and began operating as a Ransomware-as-a-Service with affiliate support and configurable builds.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

130 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Emergence and Operations of The Gentlemen Ransomware-as-a-Service Group | Mallory