The Gentlemen is a fast-growing ransomware-as-a-service (RaaS) operation that emerged in mid-2025 and became one of the most active ransomware groups during 2026. Multiple investigations have linked its formation to operators or affiliates previously associated with Qilin before splitting off to run an independent program. The group operates with a core team supported by affiliates and a revenue-sharing model, and leaked internal communications indicate a relatively small central staff coordinating a broader partner-driven intrusion ecosystem. The group conducts financially motivated ransomware and extortion operations against organizations across North America, South America, Europe, Asia, and Oceania. Reported victims and trend reporting show activity affecting business services, healthcare, manufacturing, technology, construction, financial services, energy and utilities, retail, hospitality, and professional services. The Gentlemen has been especially prominent in South America while also maintaining substantial activity in North America and Europe. The Gentlemen’s operations rely on common but effective enterprise intrusion paths rather than novel exploitation. Reported initial access methods include scanning for exposed SSL VPN infrastructure, brute-force activity, abuse of leaked or purchased credentials, and use of access broker-supplied access. Internal chat leaks and incident reporting indicate frequent targeting of Fortinet and FortiGate environments. Once inside a network, the group performs internal reconnaissance, identifies domain controllers, file servers, backup infrastructure, and business-critical databases, then escalates privileges through Active Directory abuse and moves laterally across the environment. The actor has demonstrated strong emphasis on data theft and backup disruption in addition to ransomware deployment. Operators have been observed prioritizing high-value databases, staging SQL backups for theft, disabling or evading security tooling including EDR, and interfering with backup systems to increase extortion pressure. Available reporting indicates that The Gentlemen uses both encryption and stolen-data extortion, consistent with the broader shift in the ransomware ecosystem toward leak-site pressure and double extortion. The group has also been associated with operational use of generative AI during intrusions. A suspected affiliate linked with medium confidence to The Gentlemen used Claude Code to assist with breaching VPN appliances, credential theft, reconnaissance, firewall modification, persistence creation, and SQL database exfiltration. Separate reporting on leaked internal materials indicates the group also used AI-assisted coding tools to accelerate development of ransomware infrastructure and administrative tooling. These cases suggest AI is being used to compress development and operator workflow rather than replace experienced intrusion tradecraft. Leaked Russian-language internal chats exposed discussions around target selection, reconnaissance, lateral movement, EDR evasion, backup targeting, and encryption workflows. The chats indicate deliberate victim selection based on revenue, sector, geography, and operational sensitivity, including interest in critical infrastructure and organizations under strong business continuity pressure. Known aliases include gentleman, gentlemen, gentleman_group, gentleman_ransomware_group, gentlemen_raas_affiliates, Storm-2697, and related naming variants.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
14 malware families attributed to this actor across reporting.
9 additional families tracked in Mallory.
10 CVEs this actor has used in observed campaigns. 10 of them exploited in the wild.
Recommendations Initial Access: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2024-55591 (Fortinet's FortiOS and FortiProxy)
Recommendations Initial Access: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-33073 (Windows SMB Client)
Recommendations Initial Access: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-32433 (Erlang/OTP SSH server)
Privilege Escalation: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-7771 ( ThrottleStop.sys driver)
NetLogon CVE-2020-1472 ("ZeroLogon") TheGentlemen
5 more CVEs tied to this actor tracked in Mallory.
256 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed among the most active ransomware groups in the reporting period discussed.
Ransomware group whose public claim volume dropped sharply week-over-week, from 68 to 21 claims, contributing significantly to the overall decline in weekly claims.
A suspected affiliate of this ransomware-as-a-service operation used AI extensively during intrusions, including breaching exposed VPN appliances, conducting LDAP pass-back credential theft, creating hidden VPN accounts, mapping internal networks, identifying backup infrastructure, and exfiltrating SQL database backups from multiple victim organizations.
Ransomware intrusion activity in which the operator used Claude Code during compromises of six organizations to generate reconnaissance and exploitation commands, write malicious scripts, modify firewall policies, analyze business systems, run SQL Server backup commands, and stage data for exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.