The Gentlemen is a Russia-based ransomware-as-a-service (RaaS) operation, tracked by Sophos as GOLD SHERWOOD and also known as Storm-2697. Active since 2025, it is assessed to have evolved from the ArmCorp affiliate group following disputes with the Qilin ransomware operation. The group is led and administered under the aliases hastalamuerte and zeta88; its ecosystem includes affiliates and operators associated with access, infrastructure, exploitation, hands-on-keyboard operations, lateral movement, evasion, and ransomware deployment. The operation conducts high-volume double-extortion attacks, exfiltrating selected victim data before encrypting enterprise environments and threatening publication through a leak site. It also supports data-theft-only extortion. Observed initial-access methods include stolen VPN credentials, exposed firewall-management interfaces, and exploitation of unpatched internet-facing systems. Affiliates use legitimate credentials, RDP, remote-access tunnels, credential dumping, and privileged-account changes to expand access and establish fallback access paths. The Gentlemen conducts reconnaissance of systems, data repositories, and backup infrastructure before deployment. It impairs endpoint protections using EDR-disabling tooling and bring-your-own-vulnerable-driver techniques, weakens Microsoft Defender, disables backup and recovery services, and may clear event logs. Ransomware can be deployed locally, across network shares, or domain-wide through centralized execution. The operation has been linked to TukTuk, a cross-platform command-and-control framework with command execution, file management, host discovery, screenshot capture, and fake security-prompt credential harvesting capabilities, as well as DLL sideloading. Manufacturing, healthcare, and technology organizations are prominent targets, with activity particularly concentrated against organizations in the United States and United Kingdom.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
48 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
16 malware families attributed to this actor across reporting.
11 additional families tracked in Mallory.
10 CVEs this actor has used in observed campaigns. 10 of them exploited in the wild.
Recommendations Initial Access: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2024-55591 (Fortinet's FortiOS and FortiProxy)
Recommendations Initial Access: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-33073 (Windows SMB Client)
Recommendations Initial Access: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-32433 (Erlang/OTP SSH server)
Privilege Escalation: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-7771 ( ThrottleStop.sys driver)
NetLogon CVE-2020-1472 ("ZeroLogon") TheGentlemen
5 more CVEs tied to this actor tracked in Mallory.
280 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware-as-a-service operation whose affiliates gain access through exposed or unpatched remote infrastructure and stolen VPN credentials, conduct double extortion by exfiltrating files before encryption, disable EDR/antivirus and backup services, and rapidly deploy ransomware across Windows enterprise networks.
Conducted a ransomware attack against Seasia Infotech.
A ransomware operation associated with the TukTuk cross-platform command-and-control framework. The activity combines credential theft, host surveillance, remote command execution, data theft, defense evasion, and likely ransomware deployment.
A ransomware-as-a-service operation conducting rapid double-extortion attacks involving data theft, defense evasion, and deployment of Go-based ransomware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.