The Gentlemen is an emerging ransomware-as-a-service operation first observed in active campaigns in 2025. It is assessed as a comparatively mature and disciplined entrant in the e-crime ecosystem, using a double-extortion model that combines data theft with file encryption and threats to publish stolen information. The malware family is primarily written in Go and has variants targeting Windows, Linux, and ESXi environments, indicating an emphasis on enterprise and virtualized infrastructure.
Intrusions associated with The Gentlemen have targeted medium to large organizations across multiple countries and sectors, with notable impact on manufacturing, construction, healthcare, insurance, technology, and financial services. Reported operations show a preference for enterprise networks with exposed remote administration or security infrastructure and for environments where domain-wide deployment can maximize impact.
Observed attack chains indicate initial access through exploitation of internet-facing services or the use of compromised administrative credentials, including access to firewall or VPN management infrastructure. After entry, operators conduct internal reconnaissance and Active Directory enumeration, identify privileged accounts and key systems, and scan the environment to prepare broader compromise. Lateral movement has been carried out through remote administration tooling and SMB-based techniques, while persistence has included deployment of remote access software and changes that facilitate continued remote connectivity.
A distinguishing feature of The Gentlemen operations is aggressive defense evasion. Operators have used Bring Your Own Vulnerable Driver techniques and custom tooling to terminate or disable endpoint protection and security monitoring components, including tailored variants adapted to the victim environment. They have also modified security settings, weakened remote access protections, disabled Windows Defender protections, and removed forensic and recovery artifacts such as event logs and shadow copies. The ransomware attempts to stop backup, database, mail, virtualization, and security-related services and processes before encryption to increase operational disruption and hinder restoration.
The group has also been observed staging and exfiltrating data prior to encryption, consistent with its extortion model. Deployment has included domain-wide distribution mechanisms through shared enterprise resources, enabling rapid impact across domain-joined systems. The ransomware uses operator-controlled execution safeguards, including a required password parameter, which is consistent with deliberate hands-on-keyboard deployment rather than indiscriminate self-propagation.
Encrypted files have been observed receiving a characteristic new extension, and the malware drops a dedicated ransom note to initiate negotiations. Public reporting and underground advertising indicate that The Gentlemen operates an affiliate-based RaaS model with centralized control over core infrastructure such as leak-site operations, while affiliates conduct intrusions and victim engagement. Overall, The Gentlemen represents a cross-platform enterprise ransomware threat combining credential or access abuse, reconnaissance, lateral movement, defense impairment, data exfiltration, and encryption for impact.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Group-IB described how affiliates conducted reconnaissance to identify internet-exposed FortiGate firewall management interfaces vulnerable to CVE-2024-55591.
Operators scanned for and exploited internet-facing vulnerabilities including the FortiOS authentication-bypass flaw CVE-2024-55591, alongside older Active Directory weaknesses like ZeroLogon and PetitPotam.
Operators scanned for and exploited internet-facing vulnerabilities including the FortiOS authentication-bypass flaw CVE-2024-55591, alongside older Active Directory weaknesses like ZeroLogon and PetitPotam.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In August 2025, we investigated a new ransomware campaign orchestrated by The Gentlemen... The ransomware drops the following ransom note and appends the following extension: README-GENTLEMEN.txt ... .7mtzhh
30 distinct techniques documented for this family, organized by ATT&CK tactic.
The threat actor obtained initial access ... by using compromised user credentials to authenticate to a Fortinet SSL VPN service. The absence of MFA enabled the actor to gain access.
a malicious Group Policy Object (GPO) that executed staged ransomware binaries within SYSVOL/NETLOGON via scheduled tasks across the environment
a malicious Group Policy Object (GPO) that executed staged ransomware binaries within SYSVOL/NETLOGON via scheduled tasks across the environment
The threat actor obtained initial access ... by using compromised user credentials to authenticate to a Fortinet SSL VPN service. The absence of MFA enabled the actor to gain access.
net1 localgroup administrators itadmin /add ... net group "domain admins" ldap /add /domain ... net user administrator qwertyu1 /domain.
The attacker modified the registry to enable [RDP] at the system level: reg add HKLM\System\CurrentControlSet\Control\Terminal Server /v fDenyTSConnections /d 0 /f.
a malicious Group Policy Object (GPO) that executed staged ransomware binaries within SYSVOL/NETLOGON via scheduled tasks across the environment
The threat actor obtained initial access ... by using compromised user credentials to authenticate to a Fortinet SSL VPN service. The absence of MFA enabled the actor to gain access.
net1 localgroup administrators itadmin /add ... net group "domain admins" ldap /add /domain ... net user administrator qwertyu1 /domain.
Prior to encryption, the actor ... deleted shadow copies, cleared event logs, and removed forensic artifacts.
The attacker also deleted the Application, System, and Security logs on multiple hosts.
The attacker began lateral movement via Remote Desktop Protocol (RDP), authenticating in rapid succession to multiple internal systems using valid domain credentials.
When the ransomware is executed, files are encrypted and assigned a six-character extension. Ransom notes named README-GENTLEMEN.txt are dropped across all affected directories.
Threat actors use service configuration commands to disable backup and recovery services ... sc config VeeamBackupSvc start= disabled.
By disabling these services, the attacker ensures that backup agents cannot initiate recovery processes, and enterprise backup platforms are rendered ineffective.
79 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware used in a double-extortion campaign. It is deployed domain-wide via NETLOGON, requires an 8-byte --password parameter, encrypts files with the .7mtzhh extension, drops README-GENTLEMEN.txt, stops backup/database/security services and processes, disables Windows Defender, clears logs, deletes shadow copies, and self-deletes via a batch script after execution.
Ransomware associated with a RaaS operation using dual-extortion (data theft and encryption) and described as employing advanced evasion/persistence techniques and scalable deployment across industries and geographies.
RaaS ransomware group (emerged mid-2025 per content) using dual/double-extortion tactics (data theft plus encryption), with advanced evasion/persistence and scalable cross-platform deployment; targets multiple industries globally.
Cross-platform double-extortion ransomware operated as a RaaS. Exfiltrates data, encrypts systems, and threatens publication on a leak site. Supports Windows/Linux/ESXi (and advertised NAS/BSD), uses password-protected execution, and appends the .7mtzhh extension while dropping README-GENTLEMEN.txt ransom notes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.