The Gentlemen ransomware group has rapidly established itself as a significant threat actor since its emergence around July 2025, leveraging a Ransomware-as-a-Service (RaaS) model and advanced dual-extortion tactics. The group has claimed at least 48 victims within a three-month period, utilizing the XChaCha20 encryption algorithm to lock files and exfiltrating sensitive business data to pressure organizations into paying ransoms. Their operations are characterized by a combination of established ransomware techniques and innovative strategies, including the development of their own RaaS platform after experimenting with various affiliate models, which has enabled them to quickly adapt to new attack vectors and maintain persistence against targeted organizations.
Threat intelligence reports highlight that The Gentlemen's data leak site is active, and the group has demonstrated a willingness to publish stolen data if ransom demands are not met. Their evolution from testing other ransomware platforms to building a proprietary service underscores their technical sophistication and intent to scale operations. Security professionals are advised to monitor for indicators of compromise related to The Gentlemen and to ensure robust data protection and incident response measures are in place to mitigate the risk posed by this rapidly evolving ransomware group.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
23 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-30, Gurucul published threat research describing previously undocumented The Gentlemen tradecraft, including custom backdoors, reconnaissance activity, and network sniffing capabilities. The report also shared indicators of compromise, including 81.177.215.15 and numerous MD5 hashes, plus detection queries for identifying related activity.
On 2026-06-18, ESET reported that The Gentlemen centrally develops and supplies endpoint security killing tools to affiliates through an in-house framework it named GentleKiller. The research described at least eight variants that impersonate legitimate software, use vulnerable or malicious kernel drivers, and target more than 400 process names tied to 48 security products, while also standardizing imported tools such as HexKiller, ThrottleBlood, and HavocKiller.
Breachcache published a case study of a three-day intrusion attributed to a new The Gentlemen affiliate that began with SonicWall SSL VPN credential spraying and escalated to Domain Admin via an AD CS ESC1 misconfiguration, followed by PKINIT, UnPAC-the-hash, DCSync, backup credential theft, and rclone exfiltration. On the third day, the affiliate deployed a Go-based Gentlemen payload through Group Policy, but Microsoft Defender Tamper Protection blocked execution on some hosts, limiting encryption mainly to the domain controller, backup server, and weaker-protected systems.
By 2026-06-13, The Gentlemen had listed 483 victims across 66 countries, marking a substantial increase from previously reported totals and reinforcing its status as one of 2026's most prolific ransomware brands. The report said the victim base was broadly international, with notable activity across Latin America, Europe, and Asia and only about 15% of victims in the United States.
In May 2026, The Gentlemen publicly recruited affiliates on cybercrime forums and reportedly secured an official partnership with BreachForums. The program advertised a 90% revenue share, marking a specific expansion step in its ransomware-as-a-service operations.
On 2026-06-11, PRODAFT reported that The Gentlemen evolved from the financially motivated affiliate group Phantom Mantis before becoming an independent RaaS-style partnership in July 2025. The report said the operation is led by the Russian-speaking actor LARVA-368, linked with high confidence to Alexander Andreevich Yapaev of Izhevsk, Russia.
On 2026-06-10, Krebs on Security reported that multiple intelligence and OSINT sources linked The Gentlemen administrator aliases 'hastalamuerte' and 'Zeta88' to Alexander Andreevich Yapaev of Izhevsk, Russia. The report said leaked backend data indicated this administrator assembled the ransomware locker and panel, managed payments, and received 10 percent of ransom proceeds.
The reference says The Gentlemen ransomware group carried out a ransomware attack on Romanian state energy operator Complexul Energetic Oltenia, adding a newly disclosed victim to the campaign. The article presents this as part of the group's documented incident activity in 2026.
On 2026-06-02, Securelist published research saying The Gentlemen was operating not only its mature Go ransomware family but also an emerging Windows-focused C-based variant using AES-256-GCM plus RSA. The report also described a custom Go backdoor communicating with 81.177.215[.]15:9443 and detailed reconnaissance, lateral movement, and defense-evasion tradecraft used in the group's intrusions.
On 2026-05-28, Microsoft published research on The Gentlemen ransomware, which it tracks as Storm-2697, detailing the malware's Go-based encryptor, hybrid Curve25519 and XChaCha20 encryption, and aggressive self-propagation across Windows networks using multiple lateral movement methods. The report also provided detections, hunting guidance, and mitigations including Defender protections, attack surface reduction rules, and EDR controls.
NTT reported that The Gentlemen had become one of the most active ransomware operators, accounting for 10% of observed attacks and ranking second only to Qilin. The report said the group primarily targeted industrial and IT organizations, focused heavily on Europe including the UK and Germany, and named victims including Synergy France, UK Electronics, and Equity Life.
On 2026-05-21, Huntress published analysis of two post-incident The Gentlemen ransomware deployments affecting a shipping and transportation organization and a construction company. The report documented defense-evasion and execution tradecraft including scheduled tasks, PowerShell-based Microsoft Defender tampering, selective clearing of Windows logs, use of a SOCKS proxy beaconing to 193.233.202[.]17, and redeployment of the encryptor from a NETLOGON share after initial execution was blocked.
On 2026-05-18, LevelBlue assessed that The Gentlemen was likely not a wholly new operation but a continuation or reorganization of prior affiliate activity associated with the Qilin ecosystem and the Russian-speaking actor "hastalamuerte." This represented a new attribution and lineage assessment for the ransomware group.
By 2026-05-11, stolen data from The Gentlemen ransomware group had been offered for sale on Breached and then released publicly, exposing internal chats, victim information, operational data, and a bitcoin wallet address. Analysis of the leak revealed details about the group's infrastructure management, targeting, OPSEC, use of compromised Fortinet credentials, and enterprise-focused intrusion tactics.
By 2026-05-10, The Gentlemen had publicly claimed 352 attacks in the first half of 2026, indicating continued growth beyond the previously reported 320-plus victims. The reported victims spanned more than 70 countries, with heavy impact on professional services, manufacturing, technology, and healthcare.
On 2026-05-04, the administrator of The Gentlemen ransomware operation reportedly acknowledged that the group’s internal Rocket backend and chats had been leaked. The acknowledgment preceded the broader public release and analysis of the stolen data that exposed the group’s structure, tooling, affiliates, and negotiations.
While investigating a Gentlemen ransomware affiliate intrusion, Check Point identified a SystemBC proxy malware botnet with more than 1,570 infected hosts, largely affecting corporate and organizational environments. The researchers also disclosed new intrusion details and published indicators of compromise and a YARA rule for related activity.
Check Point Research reported that The Gentlemen had publicly claimed more than 320 victims, with most of the growth occurring in early 2026. The report characterized the group as a rapidly expanding ransomware-as-a-service operation with a broad, enterprise-focused intrusion ecosystem.
On 2026-03-19, Group-IB published research saying The Gentlemen emerged from a dispute within the Qilin ecosystem and was exposed in part by affiliate 'hastalamuerte.' The report detailed the group's use of FortiGate VPN access, automated lateral movement, credential theft, backup disruption, anti-forensics, and BYOVD-based defense evasion across Windows, Linux, and ESXi targets.
By November 2025, reporting said the operation had accumulated 48 victims over roughly a three-month period, indicating rapid growth of the campaign.
Cybereason released a detailed analysis of The Gentlemen’s Windows, Linux, and ESXi ransomware variants, describing persistence, lateral movement, defense evasion, encryption methods, and providing indicators of compromise and MITRE ATT&CK mappings.
The group rapidly started naming victims on its dark web leak site during September and October 2025, marking the public operational phase of its dual-extortion campaign.
Cybereason assessed that the ransomware group known as “The Gentlemen” emerged around July 2025 and began operating as a Ransomware-as-a-Service with affiliate support and configurable builds.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
50 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcecommunity.gurucul.com
Open sourcethecybersecguru.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourceinfosecurity-magazine.com
Open sourcesecurityonline.info
Open sourcecybereason.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.