The Gentlemen is a human-operated ransomware-as-a-service operation, also tracked as Storm-2697, that emerged in mid-2025 and rapidly became one of the most active ransomware brands by victim volume in 2026. Multiple reports assess it as having roots in the Qilin ecosystem, including prior activity under the ArmCorp name, before evolving into an independent affiliate program with an unusually aggressive revenue split favoring affiliates. The operation is associated with Russian-speaking operators and follows a double-extortion model that combines data theft with file encryption and public leak-site pressure.
The malware family is notable for cross-platform ransomware development and aggressive enterprise-scale propagation. Its primary Windows encryptor is written in Go and has been described as obfuscated with Garble, while associated variants have also targeted Linux, NAS, BSD, and VMware ESXi environments, including a C-based ESXi locker. The ransomware uses hybrid cryptography based on Curve25519 or X25519 key exchange with XChaCha20 file encryption, commonly applies partial encryption to larger files for speed, and drops a ransom note associated with the operation. Some builds require a password at launch, which appears intended to hinder sandboxing and automated analysis.
A distinguishing feature of The Gentlemen is its worm-like spreading capability. When enabled, the malware can stage itself over SMB, enumerate reachable systems, and attempt numerous remote execution methods per host, including PsExec, scheduled tasks, services, WMI, WinRM, PowerShell remoting, and Group Policy-based deployment. Reporting also describes domain-wide propagation through NETLOGON and malicious GPO changes. This propagation logic, combined with pre-encryption defense weakening on remote hosts, allows a single foothold to escalate into broad network encryption.
The operation consistently demonstrates strong defense-evasion tradecraft. Observed behavior includes disabling Microsoft Defender, adding exclusions, deleting shadow copies, clearing Windows event logs, deleting forensic artifacts, stopping backup, database, virtualization, and security-related processes and services, and optionally wiping free space or self-deleting after execution. The group is also associated with dedicated security-killing tooling, including the GentleKiller framework and other EDR-killer utilities, as well as bring-your-own-vulnerable-driver techniques used to terminate protected security products. At least one intrusion involved suspected zero-day exploitation to disable endpoint defenses.
The Gentlemen’s intrusion lifecycle extends well beyond encryption. Reported operations include exploitation of internet-facing edge infrastructure, brute-force activity, use of stolen or leaked credentials, cooperation with initial access brokers, Active Directory reconnaissance, credential theft, privilege escalation, lateral movement, persistence through scheduled tasks and autoruns, and data exfiltration prior to ransomware deployment. Associated tooling and infrastructure have included custom Go backdoors, proxy malware, remote administration utilities, and common post-exploitation frameworks.
Initial access is most strongly associated with exploitation of exposed perimeter systems rather than phishing-centric delivery. Repeated reporting links the group to exploitation of edge-device vulnerabilities, especially in VPN and firewall appliances, as well as credential abuse against remote access services. The operation has also been linked to brute-force campaigns, NTLM relay-related activity, and use of compromised enterprise credentials and session material obtained from stealer ecosystems.
Victimology indicates broad global targeting across dozens of countries, with recurring impact in manufacturing, business services, technology, healthcare, transportation, financial services, construction, logistics, and other enterprise sectors. Manufacturing is repeatedly highlighted among the most affected sectors, consistent with the group’s focus on organizations where operational disruption increases ransom pressure. The Gentlemen’s combination of cross-platform lockers, rapid propagation, mature affiliate support, and strong anti-defense tradecraft makes it a high-impact ransomware threat to Windows-centric enterprise networks and mixed Windows-Linux-ESXi environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Privilege Escalation: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-7771 ( ThrottleStop.sys driver) | The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS.
Recommendations Initial Access: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-32433 (Erlang/OTP SSH server) | The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS.
Recommendations Initial Access: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-33073 (Windows SMB Client) | The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS.
Recommendations Initial Access: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-55182 (React2Shell) | The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS.
Recommendations Initial Access: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2024-55591 (Fortinet's FortiOS and FortiProxy) | The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS.
Common Vulnerabilities Exploited CVE-2023-27532 Veeam Backup & Replication Missing authentication targeted for backup destruction Critical Patching recommended | The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.
Common Vulnerabilities Exploited CVE-2024-37085 VMware ESXi Authentication bypass ESXi locker deployment vector High Patching recommended | The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.
The Gentlemen surfaced as a ransomware operation in September 2025 and by June 13, 2026 had listed 483 victims on their dark-web leak site, 380 of them in 2026 alone.
The Gentlemen surfaced as a ransomware operation in September 2025 and by June 13, 2026 had listed 483 victims on their dark-web leak site, 380 of them in 2026 alone.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS.
The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025. Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS.
The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025.
The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.
The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026... the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation.
This year saw the emergence of The Gentlemen, a prominent example of a group operating under the ransomware-as-a-service (RaaS) model.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware uses WMI via wmic.exe to create remote processes... The first command executes the defense evasion blob, the second runs the payload from the infected host’s SMB share, and the third runs the pre-staged copy from the target’s local C:\Temp directory.
To get the payload running, the malware tries as many as 21 different remote execution methods per target, including remote file copying, PsExec, scheduled tasks, Windows services, and PowerShell based techniques.
When the -- system argument is provided... the malware creates a scheduled task to re-execute itself as SYSTEM... The encryptor can establish persistence for itself through two mechanisms: scheduled tasks and registry keys.
This is complemented by the use of Cobalt Strike, Mimikatz, and domain-wide propagation via GPO, indicating a tightly coordinated, human-operated attack workflow...
To get the payload running, the malware tries as many as 21 different remote execution methods per target, including remote file copying, PsExec, scheduled tasks, Windows services, and PowerShell based techniques.
When the -- system argument is provided... the malware creates a scheduled task to re-execute itself as SYSTEM... The encryptor can establish persistence for itself through two mechanisms: scheduled tasks and registry keys.
To get the payload running, the malware tries as many as 21 different remote execution methods per target, including remote file copying, PsExec, scheduled tasks, Windows services, and PowerShell based techniques.
When the -- system argument is provided... the malware creates a scheduled task to re-execute itself as SYSTEM... The encryptor can establish persistence for itself through two mechanisms: scheduled tasks and registry keys.
Before touching a single file, the ransomware works to disable Microsoft Defender, wipe forensic logs... It also clears command history
In addition to terminating processes, the malware disables and stops a list of Windows services using the commands...
After dropping PsExec, the malware attempts to enumerate and discover remote systems on the network, including workstations, servers, and domain controllers. Each discovered host becomes a candidate target for propagation.
The -- spread argument accepts either explicit credentials in domain/user:password format for authenticated lateral movement, or an empty string to reuse the current session’s authentication token.
the malware pulls in a legitimate system tool called PsExec... and starts scanning the network for reachable machines, including regular workstations, servers, and domain controllers.
The malware stops a list of running processes using the command... The table below summarizes the different categories and processes being targeted.
The malware can only perform this task if it’s executed from an account with administrator privilege.
To get the payload running, the malware tries as many as 21 different remote execution methods per target, including remote file copying, PsExec, scheduled tasks, Windows services, and PowerShell based techniques.
publishing it over a hidden network share configured for anonymous access... re-enabling an outdated and insecure version of the file sharing protocol.
delete Volume Shadow Copies twice over using two separate commands for reliability. It also clears command history and deletes backup and recovery tools to make restoring systems without paying much harder.
For the actual encryption, the malware uses a hybrid approach pairing Curve25519 elliptic curve cryptography with the XChaCha20 stream cipher, generating a unique key for every single file it touches.
In addition to terminating processes, the malware disables and stops a list of Windows services... backup, storage, and recovery software... EDR... Microsoft Exchange...
Against each target, the malware first runs a script that weakens the remote machine’s defenses, disabling security monitoring, turning off firewall protection... Before touching a single file, the ransomware works to disable Microsoft Defender
Defense evasion: Microsoft Defender disabled, exclusions added, Security event log cleared ... On the backup server they disabled Microsoft Defender real time protection at 20:51 UTC ... Every time the payload ran it ... added Microsoft Defender process and path exclusions.
177 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
38 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware-as-a-service operation that also functions as an Initial Access Broker, providing affiliates access to pre-exploited FortiGate devices and deploying cross-platform lockers against Windows, Linux, and ESXi environments.
A ransomware-as-a-service operation active since at least July 2025. It uses ransomware variants written in C and Go, employs multiple initial access techniques, and has used custom tooling including a Go-based backdoor and the GentleKiller EDR-killer framework to improve defense evasion and enterprise impact.
Mentioned only in passing as related reading about ransomware cleanup, not as part of the primary malware discussed.
A human-operated ransomware-as-a-service operation using a Go-based cross-platform encryptor with self-propagation, double extortion, data exfiltration, and extensive defense evasion including BYOVD-based EDR/AV killing.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.