The Gentlemen is a Russian-speaking ransomware-as-a-service (RaaS) and extortion operation that emerged in July–August 2025. Also tracked as Storm-2697 and referred to as Gentleman, Gentlemen, and The Gentleman, it operates through ransomware operators and affiliates. Its targeting spans industrial and engineering businesses, technology providers, healthcare organizations, public-sector entities, and financial services across multiple countries. It deploys ransomware, steals sensitive information, negotiates extortion demands, and maintains a darknet leak site. Its geographic origin has not been conclusively established. Its intrusion activity includes FortiGate-focused initial access, credential theft, lateral movement, cloud-storage exfiltration, and ransomware deployment. Associated tooling includes the custom G-BOT command-and-control platform. In a documented affiliate intrusion, a malicious MSI installer impersonating the Sysinternals RAMMap utility deployed EtherRAT. The implant retrieved mutable command-and-control configuration from an Ethereum smart contract, allowing operators to replace command-and-control destinations without reinstalling the malware. The attackers subsequently stole credentials, installed remote-management tools, moved laterally, exfiltrated data to Wasabi using Rclone, and deployed ransomware through a malicious Group Policy Object. EtherRAT use is established for an affiliate intrusion, not for every affiliate. The operation also analyzes stolen material to support subsequent compromises, including client-credential analysis and creation of an unauthorized Okta account. It has used Kimi, DeepSeek, Qwen, and HUIHUI-AI models to automate payload generation, technical analysis, and triage of exfiltrated personally identifiable information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
65 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
33 malware families attributed to this actor across reporting.
28 additional families tracked in Mallory.
11 CVEs this actor has used in observed campaigns. 11 of them exploited in the wild.
Initial Access T1190 — Exploit Public-Facing Application CVE-2024-55591 (FortiOS auth bypass) confirmed exploited. Kunder: “CVEs: [CVE-2024-55591]”. zeta88: “Target is confirmed as vulnerable to CVE-2024-55591, proceeding with exploitation” | “CVE-2024-55591 Fortinet authentication bypass… Primary initial access vector.” The report also quotes an operator: “Target is confirmed as vulnerable to CVE-2024-55591, proceeding with exploitation.”
Recommendations Initial Access: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-33073 (Windows SMB Client)
Recommendations Initial Access: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-32433 (Erlang/OTP SSH server)
We also observed traces suggesting the exploitation of CVE-2020-1472 (Zerologon) and the vulnerabilities associated with MS17-010.
Privilege Escalation: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-7771 ( ThrottleStop.sys driver)
6 more CVEs tied to this actor tracked in Mallory.
315 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware-as-a-service operator whose infrastructure, tooling, negotiation channels, and ransom-note template supported Azazel's compromises. According to the report, Azazel diverted victim publication and extortion proceeds to his independent LEAKNED operation. The content also associates broader Gentlemen affiliate activity with evolving object-storage exfiltration tools and MEGA transfers, but does not establish that every technique used by Azazel is standard across the group.
Reportedly conducted a ransomware attack against Center State Engineering, a civil engineering consultancy in New Jersey, United States. The report dates the breach to October 3, 2026, and discovery to October 4, 2026. It lists 340 GB associated with the incident but provides no technical evidence establishing exfiltration, encryption methods, or the malware family used. Although the sector field says Manufacturing, the victim description identifies an engineering consultancy.
The Gentlemen lists Center State Engineering, a US civil engineering consultancy, as a victim and claims 340GB of stolen data. The listing was discovered on October 4, 2026; no ransom amount, deadline, attack vector, or supporting data samples are provided.
The report attributes a ransomware attack against Aware, Inc., a US biometrics and identity-verification software company, to thegentlemen. It lists the breach date as September 30, 2026, and discovery as October 3, 2026. The incident summary references 400 GB of data but does not establish whether that volume was stolen, encrypted, or leaked.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.