The Gentlemen is a financially motivated ransomware-as-a-service (RaaS) operation that emerged in mid-to-late 2025 and rapidly became one of the most active extortion groups in 2026. It is also tracked as Storm-2697, and reporting has linked its operators to prior activity associated with ArmCorp, an affiliate of the Qilin ecosystem. Known aliases include Gentleman, Gentlemen, Gentleman Group, Gentlemen RaaS Affiliates, Gentlemen Ransomware Group, The Gentleman, and The Gentlemen. The group operates an affiliate-based model and has been noted for unusually aggressive recruitment and revenue-sharing terms, including offers of very high affiliate payouts. It has recruited through underground forums and has sought not only affiliates but also penetration testers and initial access brokers, reflecting a scalable criminal service model. Some reporting also describes the operation as combining RaaS activity with initial-access brokerage. The Gentlemen primarily targets enterprise environments where operational disruption creates strong leverage for extortion. Victimology spans a wide range of sectors, including manufacturing, healthcare, transportation and logistics, energy, public sector entities, business services, and infrastructure-related organizations. Geographic targeting has been observed across Southeast Asia, South America, and Western Europe, with some researchers noting comparatively less emphasis on the United States than many peer ransomware groups. The group has nevertheless claimed victims across dozens of countries and has been assessed as one of the fastest-growing ransomware operations by victim volume. Operationally, The Gentlemen uses both encryption and data-extortion tactics. Its intrusions have been associated with multiple initial access methods, including exploitation of edge-device vulnerabilities, brute-force activity, use of leaked or stolen credentials, and cooperation with access brokers. The group deploys cross-platform ransomware variants written in C and Go, enabling attacks against Windows, Linux, and ESXi environments. Researchers have also linked the operation to a custom Go backdoor and to sophisticated pre-encryption tooling intended to weaken endpoint defenses. A defining characteristic of The Gentlemen is its emphasis on defense evasion, particularly the development and maintenance of endpoint detection and response killing tools for affiliate use. Its tooling includes the GentleKiller framework, which is designed to systematically disable or impair security products before ransomware deployment. This focus on EDR suppression has been described as a tactical differentiator within the ransomware ecosystem and indicates a comparatively mature tooling pipeline for an operation of its age. The group has also been cited as an example of how mainstream and alternative AI platforms are being incorporated into routine cybercriminal workflows. Members have reportedly evaluated commercial AI models based on the restrictiveness of their safeguards and used AI assistance to accelerate internal tool development, including management infrastructure. This reflects broader criminal adoption of AI for operational efficiency rather than a unique capability exclusive to this actor. By 2026, The Gentlemen had risen to the top tier of global ransomware activity, ranking among the most prolific groups by publicly claimed victims and, in some reporting, overtaking established competitors during peak months. Its rapid growth, broad victimology, affiliate-centric structure, cross-platform encryptors, and strong investment in defense-evasion tooling make it a significant enterprise ransomware threat.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 malware families attributed to this actor across reporting.
8 additional families tracked in Mallory.
10 CVEs this actor has used in observed campaigns. 10 of them exploited in the wild.
Recommendations Initial Access: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2024-55591 (Fortinet's FortiOS and FortiProxy)
Recommendations Initial Access: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-33073 (Windows SMB Client)
Recommendations Initial Access: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-32433 (Erlang/OTP SSH server)
NetLogon CVE-2020-1472 ("ZeroLogon") TheGentlemen
Local Security Authority (LSA) CVE-2021-36942 ("PetitPotam") TheGentlemen
5 more CVEs tied to this actor tracked in Mallory.
221 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack and associated data breach against Ecopetrol.
Ransomware/data extortion activity targeting Military Sealift Command, with claims of stolen ITAR documentation, personal data, cargo manifests, and vessel blueprints, and threats to publish the data if contact is not made.
Conducting a ransomware attack resulting in a data breach against Advantage Home Health Care.
Conducting a ransomware attack against Sunway Scientific in Taiwan.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.