The Gentlemen, tracked by Microsoft as Storm-2697, is a human-operated ransomware-as-a-service operation active since mid-2025. It uses double extortion, stealing victim data before encrypting files and threatening publication to increase payment pressure. Public reporting links its emergence to operators previously associated with the Qilin affiliate ecosystem; the operation is commonly associated with the GOLD SHERWOOD cluster.
The ransomware is primarily a Go-based, Garble-obfuscated encryptor using Curve25519 and XChaCha20 cryptography. It targets Windows environments and has cross-platform variants or support for Linux and ESXi. Its encryption workflow can impair recovery by deleting shadow copies, terminating backup and security software, clearing event logs, and optionally wiping free disk space. It can establish persistence and self-delete after execution.
A distinguishing feature is automated worm-like propagation across Windows networks. The malware can enumerate reachable network resources and attempt remote execution using mechanisms including SMB-based copying, PsExec, WMI, scheduled tasks, service creation, and PowerShell remoting. Affiliates also use domain credentials, RDP, Group Policy, and NETLOGON-based deployment to distribute ransomware broadly within compromised environments.
The Gentlemen commonly gains initial access through compromised VPN credentials, brute force, purchased access, and exploitation of internet-facing edge infrastructure, including Fortinet, Cisco, and SonicWall products. Reported activity includes evaluation or exploitation of CVE-2024-55591, CVE-2025-32433, and CVE-2025-33073. Post-compromise operations include network and Active Directory reconnaissance, credential theft, privilege escalation, lateral movement, data exfiltration using legitimate transfer utilities, and defense evasion. Its toolkit includes GentleKiller and other BYOVD-based security-product killers.
The operation recruits affiliates and offers a high affiliate revenue share. Victims span numerous regions and sectors, notably manufacturing, education, healthcare, transportation, financial services, business services, and technology. The group has been particularly active against industrial and higher-education organizations and has affected victims across North and South America, Europe, Africa, Asia, and Australia.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
GOLD SHERWOOD began operating The Gentlemen RaaS scheme in mid-2025 as a double-extortion model, in which affiliates steal data to hold for ransom before encrypting files.
CVE-2025-33073 – NTLM reflection / NTLM relay qbit references RelayKing and shares output showing domains being scanned for NTLM relay issues, including checks that explicitly cover CVE-2025-33073. This is strong evidence that they are not just reading about the vulnerability but have integrated RelayKing into their standard reconnaissance process. | The Gentlemen ransomware-as-a-service (RaaS) operation is a relatively new group that emerged around mid-2025... The leaked Rocket backend and internal chats show that this scale is driven not by a loose crowd, but by a small, tightly coordinated core...
CVE-2025-32433 – Erlang SSH vulnerability (Cisco context) In the logs, qbit shares a proof-of-concept (PoC) for CVE-2025-32433, and zeta88 comments on its quality and applicability. This shows that the group is not simply aware of the CVE but is actively evaluating whether it can be used in real operations, specifically in environments where Cisco or Erlang-based SSH services are exposed. | The Gentlemen ransomware-as-a-service (RaaS) operation is a relatively new group that emerged around mid-2025... The leaked Rocket backend and internal chats show that this scale is driven not by a loose crowd, but by a small, tightly coordinated core...
Privilege Escalation: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-7771 ( ThrottleStop.sys driver) | The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS.
Recommendations Initial Access: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-55182 (React2Shell) | The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS.
Common Vulnerabilities Exploited CVE-2023-27532 Veeam Backup & Replication Missing authentication targeted for backup destruction Critical Patching recommended | The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.
Common Vulnerabilities Exploited CVE-2024-37085 VMware ESXi Authentication bypass ESXi locker deployment vector High Patching recommended | The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.
The Gentlemen surfaced as a ransomware operation in September 2025 and by June 13, 2026 had listed 483 victims on their dark-web leak site, 380 of them in 2026 alone.
The Gentlemen surfaced as a ransomware operation in September 2025 and by June 13, 2026 had listed 483 victims on their dark-web leak site, 380 of them in 2026 alone.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GOLD SHERWOOD began operating The Gentlemen RaaS scheme in mid-2025 as a double-extortion model, in which affiliates steal data to hold for ransom before encrypting files.
The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS.
The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS.
The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025.
The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.
The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware uses WMI via wmic.exe to create remote processes.
When the -- system argument is provided (either directly or via the -- full argument), the malware creates a scheduled task to re-execute itself as SYSTEM.
The scheduled task DefU is set to run the defense evasion blob, UpdateGU executes the payload from the infected host’s SMB share, and UpdateGU2 runs the pre-staged copy from the target’s local C:\Temp directory.
When the -- system argument is provided (either directly or via the -- full argument), the malware creates a scheduled task to re-execute itself as SYSTEM.
The scheduled task DefU is set to run the defense evasion blob, UpdateGU executes the payload from the infected host’s SMB share, and UpdateGU2 runs the pre-staged copy from the target’s local C:\Temp directory.
The commands copy the malware executable into C:\Temp, creates a hidden Server Message Block (SMB) share named share$ pointing to that directory, and modifies registry settings to allow anonymous access.
The malware executes the following command sequence to create three Windows services on the target host.
The GupdateS value under HKEY_LOCAL_MACHINE (HKLM) provides device-wide persistence that allows the malware to run at startup for all users, while the GupdateU value under HKEY_CURRENT_USER (HKCU) provides user-scoped persistence within the current profile.
When the -- system argument is provided (either directly or via the -- full argument), the malware creates a scheduled task to re-execute itself as SYSTEM.
The scheduled task DefU is set to run the defense evasion blob, UpdateGU executes the payload from the infected host’s SMB share, and UpdateGU2 runs the pre-staged copy from the target’s local C:\Temp directory.
Their research shows the ransomware follows a very deliberate sequence, starting with password validation and privilege escalation, then moving into defense evasion, encryption, and finally network-wide spreading.
the custom ransomware locker ... as well as the GPO-based spread mechanism and the locker’s 'spread' module.
The malware executes the following command sequence to create three Windows services on the target host.
The GupdateS value under HKEY_LOCAL_MACHINE (HKLM) provides device-wide persistence that allows the malware to run at startup for all users, while the GupdateU value under HKEY_CURRENT_USER (HKCU) provides user-scoped persistence within the current profile.
To further impede recovery efforts, the malware deletes all Volume Shadow Copies using both vssadmin and wmic... It then clears the System, Application, and Security event logs using wevtutil to remove key audit trails.
After dropping PsExec, the malware attempts to enumerate and discover remote systems on the network, including workstations, servers, and domain controllers.
The -- spread argument accepts either explicit credentials in domain/user:password format for authenticated lateral movement, or an empty string to reuse the current session’s authentication token.
the malware pulls in a legitimate system tool called PsExec... and starts scanning the network for reachable machines, including regular workstations, servers, and domain controllers.
The malware stops a list of running processes using the command: The table below summarizes the different categories and processes being targeted.
The -- spread argument accepts either explicit credentials in domain/user:password format for authenticated lateral movement, or an empty string to reuse the current session’s authentication token.
the custom ransomware locker, the RaaS panel and builder ... as well as the GPO-based spread mechanism and the locker’s 'spread' module.
The malware binary carries an embedded copy of PsExec and drops it to C:\Temp\psexec.exe on the infected device. If the embedded PsExec payload cannot be extracted successfully, the malware falls back to downloading PsExec directly from Microsoft’s Sysinternals Live service.
delete Volume Shadow Copies twice over using two separate commands for reliability. It also clears command history and deletes backup and recovery tools to make restoring systems without paying much harder.
Finally, once the environment is prepared and critical data is in their control, they deploy their custom ransomware 'locker,' which is designed to spread quickly across the network... and encrypt systems in a coordinated manner.
In addition to terminating processes, the malware disables and stops a list of Windows services.
To further impede recovery efforts, the malware deletes all Volume Shadow Copies using both vssadmin and wmic.
Before starting file encryption, the malware executes a sequence of commands to disable defensive controls and remove potential forensic artifacts.
The PowerShell commands disable Microsoft Defender real-time monitoring to remove active protection on the infected device. The malware then adds its own executable to the Defender exclusion list to avoid detection. Finally, it excludes the entire C:\ volume from scanning.
177 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
51 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A double-extortion ransomware operation supplied to affiliates by GOLD SHERWOOD. It steals data before encrypting files, targets Windows systems in the observed incidents, and also has Linux and ESXi-compatible variants. Windows locker binaries encrypt files, add a six-character extension, and drop README-GENTLEMEN.txt ransom notes.
Ransomware operation listed as the most active group by claimed victim listings in July 2026.
Relatively new ransomware operator identified as the dominant threat in South America, with significant activity also in North America and strong focus on healthcare, manufacturing, construction, and IT services.
Relatively new ransomware operator identified as the dominant threat in South America, with notable activity against healthcare, manufacturing, and IT services.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.