Gentlemen is a ransomware-as-a-service (RaaS) operation that emerged in 2025 and became one of the most active ransomware groups in 2026. It operates a double-extortion model, combining data theft with file encryption and public leak-site pressure. Reporting has linked the group to Russian-speaking operators, and multiple investigations have described its founder or leadership as tied to former Qilin affiliates; broader membership has also been associated with individuals previously involved with other ransomware ecosystems including Embargo, LockBit, Medusa, and BlackLock. Known aliases and associated handles include The Gentlemen and hastalamuerte, with zeta88 identified in internal communications as a leadership persona. Gentlemen is notable for centrally developing, maintaining, and distributing defense-evasion tooling to affiliates rather than leaving endpoint security disruption entirely to individual operators. Its best-known in-house framework, dubbed GentleKiller, is an EDR-killing suite with multiple variants that use bring-your-own-vulnerable-driver techniques to gain kernel-level access and terminate security processes. Researchers have documented variants targeting more than 400 process names associated with roughly 48 security products. The group has also integrated externally sourced EDR-killing tools, including HexKiller, ThrottleBlood, and HavocKiller, into a standardized evasion pipeline. This tooling commonly uses masquerading, fake vendor metadata, copied or invalid signatures, trusted-looking icons, and commercial protectors such as Enigma or Themida to hinder detection and attribution. Gentlemen has also shown unusual agility in operationalizing newly disclosed BYOVD proof-of-concepts within days of public release. The group’s ransomware arsenal includes a primary cross-platform Go-based encryptor used against Windows, Linux, and other environments, as well as a newer C-based encryptor observed in Windows and ESXi-related activity. In addition to encryption tooling, investigations have identified a custom Go backdoor used before encryption to maintain access, execute commands, support proxying, and facilitate continued reconnaissance and lateral movement. Gentlemen-linked activity has also involved credential theft tooling, including the Rust-based OxideHarvest stealer, although some research attributes that tool to an affiliate rather than the core operators. Initial access has been associated with exploitation of vulnerable internet-facing services, VPN gateways, and firewalls, as well as the use of stolen, weak, or default credentials and possible cooperation with access brokers. Post-compromise behavior includes internal reconnaissance, credential and traffic collection, lateral movement via remote administration mechanisms and domain-wide deployment methods, and pre-encryption attempts to disable security controls, stop virtual machines, terminate locking processes and services, and remove recovery artifacts. Victim selection appears to be centrally influenced by exposed or misconfigured FortiGate infrastructure rather than geography alone. Gentlemen’s victimology is globally distributed but is repeatedly described as less US-centric than many major ransomware peers. Observed concentrations include Southeast Asia, South America, and Western Europe, with attacks reported against large enterprises and critical infrastructure as well as organizations in manufacturing, construction, IT, finance, healthcare, logistics, government-related, and energy-linked sectors. Public reporting has also tied the group to disruptive incidents affecting industrial operations. The operation has additionally been cited as an example of criminal adoption of artificial intelligence in routine workflows. Researchers reported that members evaluated mainstream commercial AI models based on permissiveness and used AI assistance to accelerate internal tool development, including rapid creation of management tooling. This combination of high operational tempo, centralized affiliate enablement, sophisticated EDR-disruption capability, and rapid tooling adaptation has made Gentlemen a prominent ransomware threat in the 2025-2026 period.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this threat actor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.